Custody, written
in cold storage.
No exchange will ever be 100% safe. The honest question is what fails when something goes wrong, and how fast it’s contained. Here’s our answer.
Six pillars. Independent of each other.
Cold storage
95% of customer assets sit in air-gapped multi-sig vaults across geographically distributed bank-grade facilities.
Multi-signature
Every withdrawal requires multiple cryptographic signatures from independent key holders. No single signer can move funds.
DDoS posture
Multi-layer traffic filtering on the perimeter and inline rate limits at the API. The matching engine stays up under attack.
Audited
Annual SOC 2 Type II. Quarterly third-party pen tests. Public bug bounty with payouts up to $250,000.
KYC / AML
Tier-1 KYC partners. Travel Rule compliant since launch. Sanctions screening on every deposit and withdrawal.
Device hygiene
Manage and revoke device access from your settings. Instant alerts for new logins, IP changes, and 2FA resets.
The five-step incident path.
Encrypted in flight + at rest
TLS 1.3 on every connection. AES-256 on every database row. Keys rotated quarterly.
Real-time anomaly detection
ML-driven session scoring on auth + withdrawals. Suspicious actions trigger step-up checks before any state change.
Withdrawal verification
Stacked checks: 2FA, email confirmation, address whitelist, 24-hour cool-down on new addresses.
Incident response
Dedicated SOC. Sub-minute paging on critical alerts. Postmortems published in full, never summarised.
Quarterly external audits
Tier-1 firms run pen tests. Annual SOC 2 Type II review. Findings shipped to fixes inside the same release window.
Eight habits we
strongly recommend.
Enable two-factor authentication
Authenticator app preferred (Google Authenticator, 1Password, Authy). SMS is fallback only.
Use a strong, unique password
Min 12 chars. Mix of cases, numbers, symbols. Never reuse a password from any other service.
Enable withdrawal whitelist
Pre-approve withdrawal addresses. New addresses sit in a 24-hour cool-down before they’re usable.
Set an anti-phishing code
A short string we include in every email from us. If it’s missing, the email is not from us.
Audit your device list
Review the active sessions in Security settings monthly. Revoke anything you don’t recognise.
Avoid open Wi-Fi
Never sign in or trade on public networks. Use a VPN if you have to connect from a shared network.
Keep your software current
Browsers, OS, mobile app, authenticator — patch them. Outdated clients are how phishers win.
We will never ask
Worldstreet staff will never ask for your password, 2FA code, seed phrase, or private key. Report it.
Audits we sign,
others actually verify.
We don’t ask for trust. The list on the right is what independent firms have signed off on within the last 12 months.
Found a vulnerability?
We’ll pay you for it.
Public bug bounty, no NDA. Critical findings up to $250,000. Triage SLA under 4 business hours. Honest scope, no fine print.