Security Center

How we protect accounts

An honest summary of the security controls implemented on Vaultex Market today. We describe only what is actually in place — nothing aspirational.

Section 01

Authentication

Email one-time passcode on every sign-in

Users receive a one-time code by email each time they sign in. Codes expire after 10 minutes and a fresh code is required for every new session.

Bcrypt-hashed passwords

Passwords are hashed using bcrypt with a work factor appropriate for modern hardware. Plain-text passwords are never written to disk or logs.

Role-based admin access

Administrative actions are gated by role and scoped permissions. Only approved admin accounts can review KYC, approve deposits, or adjust balances.

Section 02

Account monitoring & auditability

Account activity log

Every sign-in, balance change, deposit, withdrawal, and trade is written to an account activity log visible to both the user and our compliance team.

Admin action audit

Every admin action is recorded with the actor ID, target account, and timestamp so balance adjustments and approvals are fully traceable.

Manual review of funds movement

Deposits and withdrawals are reviewed by a member of our finance team before funds move. Nothing is auto-approved on funded accounts.

Section 03

Identity verification

KYC before funding

An account cannot request a deposit or place an order until identity verification is approved. Browsing and account review are available before KYC.

Manual document review

Our compliance team manually reviews each uploaded ID document, name, and date of birth. Typical review time is one business day during published hours.

Section 04

Operational safeguards

Managed infrastructure

The platform runs on managed cloud infrastructure with regular backups and standard hardening practices. We do not operate physical hardware ourselves.

TLS in transit

All traffic between browsers and our servers is sent over HTTPS with modern TLS settings. Sensitive credentials are never sent in plain text.

Suspicious-activity flagging

Unusual patterns on funded accounts are flagged for manual review before any funds are moved off the platform.

Incident reporting & responsible disclosure

Found a security issue? Please report it privately and give us a reasonable window to respond before any public disclosure. We do not initiate legal action against good-faith researchers who follow responsible-disclosure practices.

Contact:security@vaultexmarket.comResponse window: within one business dayBusiness hours: Monday – Friday, 09:00 – 18:00 UTC