Skip to content
BTC0.4821@76,234.5014:32:18ETH2.400@2,322.5114:32:17SOL42.000@85.76014:32:16BTC0.0124@76,234.4814:32:15XRP1,240@2.47414:32:14BNB3.120@651.8414:32:13ETH0.184@2,322.4814:32:12DOGE4,820@0.1284014:32:11BTC1.2841@76,234.2014:32:10LINK84.00@27.84014:32:09SOL8.420@85.74014:32:08ADA2,100@0.8120014:32:07BTC0.0412@76,233.9014:32:06ETH4.400@2,322.4014:32:05XRP340.00@2.47114:32:04BNB0.840@651.8214:32:03BTC0.2148@76,233.6014:32:02SOL12.400@85.72014:32:01LINK14.20@27.83014:32:00ETH0.840@2,322.3814:31:59BTC3.1842@76,233.4014:31:58DOGE12,400@0.1283814:31:57
/00Trust posture

Custody, written
in cold storage.

No exchange will ever be 100% safe. The honest question is what fails when something goes wrong, and how fast it’s contained. Here’s our answer.

$250M
Insurance fund
covering exchange-held balances
95%
Assets in cold storage
multi-sig, air-gapped
0
Security breaches
since founding · 2020
24/7
Threat monitoring
in-house SOC
/01How we’re built

Six pillars. Independent of each other.

/01

Cold storage

95% of customer assets sit in air-gapped multi-sig vaults across geographically distributed bank-grade facilities.

/02

Multi-signature

Every withdrawal requires multiple cryptographic signatures from independent key holders. No single signer can move funds.

/03

DDoS posture

Multi-layer traffic filtering on the perimeter and inline rate limits at the API. The matching engine stays up under attack.

/04

Audited

Annual SOC 2 Type II. Quarterly third-party pen tests. Public bug bounty with payouts up to $250,000.

/05

KYC / AML

Tier-1 KYC partners. Travel Rule compliant since launch. Sanctions screening on every deposit and withdrawal.

/06

Device hygiene

Manage and revoke device access from your settings. Instant alerts for new logins, IP changes, and 2FA resets.

/02When something happens

The five-step incident path.

01

Encrypted in flight + at rest

TLS 1.3 on every connection. AES-256 on every database row. Keys rotated quarterly.

02

Real-time anomaly detection

ML-driven session scoring on auth + withdrawals. Suspicious actions trigger step-up checks before any state change.

03

Withdrawal verification

Stacked checks: 2FA, email confirmation, address whitelist, 24-hour cool-down on new addresses.

04

Incident response

Dedicated SOC. Sub-minute paging on critical alerts. Postmortems published in full, never summarised.

05

Quarterly external audits

Tier-1 firms run pen tests. Annual SOC 2 Type II review. Findings shipped to fixes inside the same release window.

/03Your responsibilities

Eight habits we
strongly recommend.

Enable two-factor authentication

Authenticator app preferred (Google Authenticator, 1Password, Authy). SMS is fallback only.

Use a strong, unique password

Min 12 chars. Mix of cases, numbers, symbols. Never reuse a password from any other service.

Enable withdrawal whitelist

Pre-approve withdrawal addresses. New addresses sit in a 24-hour cool-down before they’re usable.

Set an anti-phishing code

A short string we include in every email from us. If it’s missing, the email is not from us.

Audit your device list

Review the active sessions in Security settings monthly. Revoke anything you don’t recognise.

Avoid open Wi-Fi

Never sign in or trade on public networks. Use a VPN if you have to connect from a shared network.

Keep your software current

Browsers, OS, mobile app, authenticator — patch them. Outdated clients are how phishers win.

We will never ask

Worldstreet staff will never ask for your password, 2FA code, seed phrase, or private key. Report it.

/04Compliance

Audits we sign,
others actually verify.

We don’t ask for trust. The list on the right is what independent firms have signed off on within the last 12 months.

SOC 2 Type II
Certified · annual
ISO 27001
Compliant
PCI DSS Level 1
For card rails
GDPR + CCPA
EU + California

Found a vulnerability?
We’ll pay you for it.

Public bug bounty, no NDA. Critical findings up to $250,000. Triage SLA under 4 business hours. Honest scope, no fine print.