Skip to content
Security

Your data is
untouchable.

CryptoWise is built with strong security at every layer. Your portfolio, your keys, your privacy — protected by design.

AES-256

Encryption

TLS 1.3

In Transit

GDPR

Compliant

Sentry

Error Tracking

How we protect your data

Encryption at rest and in transit

Your exchange API keys are encrypted with AES-256-GCM before they touch our database. All traffic uses TLS 1.3. We only request read-only permissions — we can never move your funds.

ENC | api_key = AES-256-GCM(key, master, iv)

ENC | secret  = AES-256-GCM(secret, master, iv)

TLS | proto  = TLS 1.3 | CHACHA20-POLY1305

DB  | algo   = AES-256 | mode = GCM

SES | cookie = HttpOnly; Secure; SameSite = Lax

Secure infrastructure

Deployed on a global edge network with automatic DDoS protection, managed PostgreSQL with encrypted backups, and strict Content Security Policy headers.

Intelligent rate limiting

23 configurable tiers of per-user and per-IP rate limiting prevent brute-force attacks, API abuse, and resource exhaustion.

Complete audit trail

Every sensitive action is logged — login attempts, role changes, data exports, exchange syncs. Full context: who, what, when, and from where.

Authentication & access

Secure login

Firebase Authentication with Google OAuth and email/password. HTTP-only session cookies immune to XSS.

Role-based access

Granular RBAC (user, admin, support) with workspace-level permissions (owner, admin, member, viewer).

Bot protection

Cloudflare Turnstile CAPTCHA prevents automated signups and credential stuffing attacks.

Account security

Instant account suspension with audit trail. Login tracking with IP, device, country, and method.

Privacy first

Zero data selling

We never sell, rent, or share your trading data. No ad networks, no fingerprinting, no tracking cookies.

Sensitive data encrypted

Exchange API keys and TOTP secrets encrypted with AES-256-GCM using per-key random IVs. Database hosted on managed PostgreSQL with encrypted storage.

GDPR compliant

Full European data protection compliance. Export or delete your data at any time, no questions asked.

Minimal collection

We only collect what's necessary. No analytics trackers, no third-party cookies, no behavioral profiling.

Have a security question?

We take security seriously. Report vulnerabilities or ask questions — our team responds within 24 hours.