Security principles

Trust comes from clear boundaries.

We are building OwnCrypto to be transparent about what the website does, what the provider does, and what information should never be stored unnecessarily.

Person using a phone with a security shield

The foundation

A safe product is never a last-minute feature.

These are the technical and product principles we will keep as the account and provider integration are added.

Sensitive information stays in the right place

The payment and verification flow belongs with the approved regulated provider. OwnCrypto should avoid holding card, bank, or raw identity-document data.

Security is designed server-side

Partner keys and webhook secrets are kept in encrypted hosting settings. The browser receives only a short-lived, controlled session.

Transactions need a verified timeline

Provider updates are accepted only after signature verification, then shown as a readable status history for the correct account.

Before we go live

There is a real checklist—and we will follow it.

  • Provider production approval and allowed-domain configuration
  • Proper authentication, password recovery, and MFA decision
  • Legal pages, risk language, support processes, and jurisdiction review
  • Webhook verification, error monitoring, rate limits, and security review

Product preview

See the flow we are building.

How it works