Security
How we protect your account
Handling other people money means getting the boring parts right. Here is what we do, and what you can do alongside us.
On our side
Encrypted in transit
Every connection to the platform is encrypted. Your password is stored as a one-way hash, which means even we cannot read it.
Sign-in alerts
When your account is accessed from a device or location we have not seen before, you get an email with the details so you can act immediately if it was not you.
Identity verification
Everyone who deposits or withdraws has verified their identity. It is a legal requirement, and it makes accounts far harder to take over.
Withdrawal controls
Payout destinations are saved and reviewed. Every withdrawal request is checked by a person before funds move, and the amount is held aside so it cannot be spent twice.
A full audit trail
Every administrative action on an account is logged with who did it and when. Nothing changes on your account without a record.
Limited internal access
Staff accounts are scoped to the parts of the platform their role needs. Not everyone can see or change everything.
On your side
Use a password you use nowhere else
Most account takeovers start with a password leaked from an unrelated site. A password manager makes this painless and is the single most useful thing you can do.
Read the sign-in alerts
If you get an email about a sign-in you do not recognise, change your password straight away and open a support ticket. Do not wait to see if anything happens.
Check your payout details
Before saving a withdrawal account, read the numbers back carefully. A payment sent to the wrong account number is often impossible to recover.
Be sceptical of anyone contacting you
We will never ask for your password, and we will never message you asking you to move funds somewhere for safekeeping. Anyone who does is not us.
Spotted something worrying?
Tell us immediately. We would rather investigate a false alarm than miss a real one.