Security

Built like a vault, not an app.

Security is the product. We’d rather show you exactly where we stand than imply more than is true — so each safeguard below is marked with its real status: what’s live today, what’s being independently certified, and what is wired ahead of regulated launch.

Live
In progress
At regulated launch
I — Your assets

Where your money sits

Custody, insurance, and reserves — the things that answer "is my money actually there?" These run through regulated partners and are wired ahead of regulated launch.

Institutional custody

At regulated launch

Client assets held with a regulated institutional custodian using multi-party computation (MPC) key management and cold storage. Member assets segregated from operating funds.

Custodial insurance

At regulated launch

Insurance on custodial holdings via our custody partner’s underwriters. Coverage terms are published when the partner is confirmed.

Proof of reserves

At regulated launch

Independent reserve attestation by an external accounting firm, confirming assets meet or exceed member liabilities — published on a regular cadence.

II — Independent assurance

Checked by outsiders, not just us

Registered legal entity

Live

Operated by Perdura Capital Market Inc, a Cayman Islands exempted company (Reg. SN-305482, incorporated 3 Nov 2020) — verifiable on the government registry at verify.gov.ky. Incorporation, not a financial-services licence.

SOC 2 Type 2

In progress

Independent audit of our security, availability, and confidentiality controls. Programme underway; report published on completion.

ISO/IEC 27001

In progress

Information-security management certification. Implementation in progress ahead of launch.

KYC / AML onboarding

Live

Identity verification and anti-money-laundering screening are required before any account can hold funds.

Over-collateralized lending

Live

Every loan is backed by more than its value, with automatic liquidation buffers to protect the loan book.

III — Platform & infrastructure

Built on hardened foundations

The platform runs on named, independently-certified infrastructure, and access to your data is fenced off at every layer.

Certified data platform

Live

Built on Supabase — a SOC 2 Type 2-compliant platform — for authentication, database, and encrypted storage.

Global edge network

Live

Served over Vercel’s global edge with automatic TLS and DDoS mitigation. All traffic encrypted in transit (HTTPS).

Row-level data isolation

Live

Every member’s records are fenced off at the database with row-level security — your data is never reachable from another account.

Encrypted KYC storage

Live

Identity documents are kept in private, access-controlled storage, scoped to you and used only for verification.

Least-privilege access

Live

Administrative and service credentials are server-side only and never exposed to the browser. Admin surfaces are role-gated.

System-controlled compliance

Live

KYC approval is locked to authorized staff — members cannot alter their own verification status. Every sensitive action is validated server-side.

IV — Your account

Controls in your hands

Strong password policy

Live

Minimum-length passwords enforced at sign-up, with secure, industry-standard authentication.

Two-factor authentication

Live

Optional TOTP 2FA from an authenticator app, enforced at every login for an extra layer beyond your password.

Withdrawal address whitelisting

Live

Withdrawals and sends can only go to addresses you’ve pre-approved — enforced server-side, so funds can’t leave to an unknown destination.

Login & withdrawal alerts

In progress

Real-time notifications for sign-ins and withdrawal requests, so you see account activity as it happens. Rolling out.

Questions about how we hold your money?

Read the Risk Disclosure Statement and our Terms of Use, or open an account to see the platform for yourself.

Open an account