Security
How we treat custody of client assets, and how to keep your own account secure.
Cold storage custody
The majority of client assets are held in geographically distributed offline wallets, air-gapped from any internet-connected system, reducing exposure to remote attacks.
Multi-signature withdrawals
Every withdrawal requires sign-off from multiple independent key holders before funds move — no single person can move client funds alone.
Independent audits
Reserves are reviewed on a regular basis to confirm client balances are backed by assets actually held in custody.
Platform security
Passwords are never stored in plain text. Sessions are secured with signed, expiring tokens, and admin actions (approving deposits, withdrawals, and account changes) are restricted to verified admin accounts only.
Keeping your own account secure
- — Use a unique, strong password you don't reuse elsewhere.
- — Never share your password or one-time codes with anyone, including someone claiming to be Cryptara support.
- — Double-check the destination address before submitting a withdrawal — transactions can't be reversed once sent.
- — Log out on shared or public devices.
Report a security issue
If you believe you've found a security vulnerability, please report it to cryptaraholding@outlook.com rather than disclosing it publicly. We take these reports seriously and will respond promptly.