Security
What actually protects capital day-to-day: custody structure, key management, and operational controls.
Custody
Client assets sit in segregated wallets with regulated institutional custodians. Withdrawal authorisation requires multiple approvers under a strict allow-list of destinations.
Key management
Trading and treasury keys are held in HSMs (hardware security modules). Multi-signature schemes gate every transfer above operational thresholds.
Access control
Role-based access, mandatory MFA (TOTP + WebAuthn), and audit logs for every privileged action. Access reviews are performed quarterly.
Application security
TLS everywhere, strict CSP, dependency scanning on every deploy, and periodic third-party penetration testing.
What security cannot do
Security controls protect assets from unauthorised access. They cannot protect against trading losses or market events — that is what the risk-management framework is for.
Frequently asked questions
- Where are the assets held?
- In segregated custody with regulated institutional custody partners. Assets are not commingled with the operating company's balance sheet.
- Is 2FA supported on my account?
- Yes — TOTP is required. Hardware keys (WebAuthn) are supported and recommended.
- What happens if the operating company fails?
- Assets in custody remain segregated and are not part of the operating company's estate. Recovery is coordinated through the custodian.