Compliance
Security
Controls implemented in the platform, and how to report a vulnerability. We describe what is built — we do not claim certifications we do not hold.
Controls
What is implemented
Multi-factor authentication
MFA on accounts, with passkey-ready authentication.
Role-based access control
Least privilege, with step-up authentication on high-risk actions.
Encryption
Encryption in transit and at rest, with managed secret storage.
Key custody
Production certificate keys are designed for HSM-backed custody. Keys are never held in application configuration.
Audit logging
Immutable audit events for material actions, retained for review.
Rate limiting
Request limits, secure headers and a content security policy.
Not yet held
What we do not claim
No SOC 2 report
Bitdax has not completed a SOC 2 examination. We will publish the report reference when one exists.
No ISO 27001 certificate
No ISO 27001 certification has been granted.
No penetration test published
Independent testing is planned before any production release.