Cold/hot wallet layering
The wallet design plans cold/hot layering, key-permission separation, and multi-party approval to limit online funds, with withdrawal limits and exception review. Key generation, storage, use, and recovery will follow independent processes.
Segregation and reconciliation
Client assets and firm assets will be managed separately, with ongoing checks of on-chain balances, internal ledgers, and client liabilities, plus investigation and handling of differences. Transfers, authorization changes, and material fund operations will keep auditable records.
Account protection
Account-level plans include two-factor authentication, device recognition, API permission controls, and withdrawal-address allowlists.
System protection
System-level plans include communications encryption, access control, and security monitoring to identify unusual access and potential attacks.
Backup, recovery, and drills
Backup and recovery, incident drills, and security assessments will test defenses, with an incident-response process.
Major incident response
In a material incident, the platform may restrict operations, restore services, and notify users based on impact, then track remediation and improvements.