Skip to main content

Compliance

Security

Controls implemented in the platform, and how to report a vulnerability. We describe what is built — we do not claim certifications we do not hold.

Controls

What is implemented

Multi-factor authentication

MFA on accounts, with passkey-ready authentication.

Role-based access control

Least privilege, with step-up authentication on high-risk actions.

Encryption

Encryption in transit and at rest, with managed secret storage.

Key custody

Production certificate keys are designed for HSM-backed custody. Keys are never held in application configuration.

Audit logging

Immutable audit events for material actions, retained for review.

Rate limiting

Request limits, secure headers and a content security policy.

Not yet held

What we do not claim

No SOC 2 report

Bitdax has not completed a SOC 2 examination. We will publish the report reference when one exists.

No ISO 27001 certificate

No ISO 27001 certification has been granted.

No penetration test published

Independent testing is planned before any production release.