1. Governance and accountability
Security and compliance responsibilities should be assigned, documented and reviewed. Policies, risk assessments, training, access approvals and changes should have accountable owners and evidence.
2. Account protection
Recommended controls include strong credential requirements, multi-factor authentication, rate limiting, suspicious-login detection, session management, withdrawal verification and secure recovery procedures.
3. Data protection
Sensitive information should be encrypted in transit and at rest, access-controlled on a least-privilege basis, logged, backed up and retained only as required. Production secrets should be isolated from public website code.
4. Transaction safeguards
Controls may include wallet screening, address validation, confirmation thresholds, withdrawal holds, behavioural monitoring, manual review and audit trails. No control eliminates all blockchain or fraud risk.
5. Vendor and infrastructure risk
Critical providers should be assessed for security, privacy, resilience, data location, subcontractors and incident obligations. Access should be limited and reviewed when roles or contracts change.
6. Availability and resilience
Backups, restoration tests, monitoring, alerting, redundancy and documented continuity plans can reduce disruption. Uptime figures must come from verified production monitoring rather than demonstration widgets.
7. Incident response
A documented process should cover detection, containment, investigation, recovery, evidence preservation, user communication and regulatory notification. Material incidents should produce corrective actions and follow-up testing.
8. What users should do
Use a unique password, enable multi-factor authentication, verify URLs, maintain device security and never share private keys, recovery phrases or one-time codes. Report suspected compromise through verified support channels immediately.

STAKE • EARN • GROW