Security is a foundation of the Platform, not a feature. This page explains how we protect the funds and data you trust us with, and how you can help. ## 1. Funds - **Segregation.** NGN wallets are held with our licensed payment partners in accounts segregated from operating funds. USD balances live on-chain in platform wallets protected by hardware-backed key management. - **Reconciliation.** Every deposit, trade, settlement and cash-out is written to a double-entry ledger and reconciled against on-chain and bank data continuously. Discrepancies raise an incident immediately. - **Cash-out controls.** Cash-outs go only to bank accounts and wallets in your name and are held for review when they trip fraud rules. ## 2. Accounts - **Strong authentication.** Sign-in requires email verification and, for sensitive actions, a one-time PIN sent to your registered device or email. - **Session hygiene.** Sessions expire after inactivity, and you can revoke every session from Settings → Security. - **Change alerts.** We email you when your password, phone number, bank account or cash-out address changes. Any of those messages you did not authorise means someone has your credentials — reset your password and contact us immediately. ## 3. Data - **Encryption in transit.** All traffic to and from the Platform uses TLS 1.3. - **Encryption at rest.** Sensitive fields (identity documents, bank details, secrets) are encrypted with envelope encryption; keys are rotated on a schedule. - **Access.** Employee access is least-privilege and logged. Production changes require peer review. - **Backups.** Backups are encrypted, geographically redundant and tested regularly. ## 4. What you can do - Use a unique, strong password and a password manager. - Enable device biometrics on your phone. - Never share your PIN, password, one-time codes or seed phrase with anyone — TradeBanta support will never ask for them. - Only download the app from official app stores or from tradebanta.com. - Verify links before you tap. Our official domain is **tradebanta.com**. ## 5. Reporting a vulnerability If you believe you have found a security issue, please email **support@tradebanta.com** with a clear description and proof-of-concept. We commit to acknowledging within 48 hours, keeping you updated on progress, and — for qualifying reports — offering a bounty. Please do not test against production users or exfiltrate real data. ## 6. Incidents We will notify affected users promptly if a security incident materially affects them and will publish a public post-mortem for platform-wide incidents.
