EN Log in Sign up
  1. Home
  2. Security
Security model

Security at Zenvorika

How customer assets are designed to be held, how accounts are protected, how incidents are handled, and what you can do to keep your own account safe.

Custody

The custody model

Zenvorika is in pre-launch and holds no customer assets today. This is the model the platform is being built to, and it will be independently reviewed before launch.

Cold storage for the majority

The target is for at least 95% of customer assets to be held in offline wallets. Their private keys are generated and stored on air-gapped hardware and never exist on an internet-connected machine.

Warm and hot tiers

A warm tier refills the hot wallet in controlled batches. The hot wallet holds only what is needed for normal withdrawal flow, sized so that its loss would be covered by reserves.

Multi-party approval

Moving funds out of cold or warm storage requires independent approvals from several key-holders in different locations, using threshold signing. No single employee can move funds alone.

Segregated customer assets

Customer balances are tracked separately from company funds and are not lent, staked or used for operations unless a customer opts into a specific product.

Account protection

Layers that protect your account

Each control assumes the one before it might fail. A stolen password alone should never be enough to move funds.

  • Two-factor authenticationRequired for log-in, withdrawals, API key creation and any security change. Authenticator apps and hardware security keys (FIDO2/WebAuthn) are supported; SMS is offered only as a backup.
  • Device managementSee every device and session with approximate location and last activity. Sign any of them out remotely. A new device triggers an email confirmation.
  • Withdrawal whitelistOnce enabled, withdrawals can only go to saved addresses. A newly added address is locked for 24 hours, and turning the whitelist off triggers a 24-hour withdrawal hold.
  • Security changes cool-downChanging your password, email or 2FA method pauses withdrawals for 24 hours, so a hijacked session cannot empty an account immediately.
  • Scoped API keysAPI keys can be read-only or trade-only, restricted to allow-listed IP addresses, and never carry withdrawal permission by default.
  • Activity alertsEmail notifications for log-ins, withdrawals, new devices and security changes, each with a one-click link to freeze the account.

Anti-phishing code

Choose a short phrase in your security settings — for example jade-harbour-42. Every genuine email from Zenvorika will include it near the top.

Phishing emails copy logos and wording, but an attacker doesn't know your code. If an email claiming to be from Zenvorika doesn't show it, don't click anything, and forward it to security@zenvorika.com.

Anti-phishing code: jade-harbour-42
This line would appear at the top of every genuine email.

Proof of reserves, in general terms

A proof of reserves shows that an exchange holds at least as much of each asset as it owes customers. Customer balances are hashed into a Merkle tree; each customer can check their own leaf is included without seeing anyone else's balance, and the tree's total is compared with wallet balances that can be verified on-chain. It shows assets at one moment in time — it doesn't prove the absence of other liabilities, which is why it works best alongside an independent review.

Incident response

When something goes wrong

No system is immune to incidents. What matters is how quickly they are found, how tightly they are contained and how honestly they are reported.

  1. Detect

    Automated monitoring of wallet flows, login patterns and infrastructure, with alerts routed to an on-call security engineer at all hours.

  2. Contain

    Affected systems can be isolated and withdrawals paused platform-wide within minutes. Pausing is a deliberate first step, not a failure mode.

  3. Investigate

    Forensic review establishes what happened, which accounts or assets are affected and whether the root cause is closed.

  4. Notify

    Affected customers are told what happened, what data or assets were involved and what they should do, as soon as facts are confirmed.

  5. Recover and review

    Services resume only after verification. A written post-incident review records causes and the changes made to prevent a repeat.

Bug bounty

Report a vulnerability

Security researchers who report vulnerabilities responsibly help keep everyone safer. A public bug bounty programme will open alongside the exchange; reports about this website are welcome now.

Rewards will scale with severity and quality of the report. Full programme terms will be published at launch.
SeverityExamples
CriticalTheft or unauthorised movement of funds, remote code execution on production, full account takeover without user interaction
HighBypass of 2FA or the withdrawal whitelist, access to other users' personal data, significant authentication flaws
MediumStored XSS, CSRF on sensitive actions, meaningful information disclosure
LowIssues with limited impact, such as missing security headers with a demonstrable effect
  • Please doTest only against your own accounts, give us reasonable time to fix before disclosure, and include clear reproduction steps.
  • Please don'tAccess other users' data, run denial-of-service or social-engineering tests, or use automated scanners that degrade service.
security@zenvorika.com
Your part

Security tips for users

Most account compromises start outside the exchange. These habits close the common routes in.

  1. Use a unique password and a password manager

    Reused passwords are the most common route into accounts. A manager also refuses to fill your password on a look-alike domain.

  2. Prefer an authenticator app or security key

    SIM-swap attacks can intercept SMS codes. A hardware key is the strongest option.

  3. Check the anti-phishing code

    Every genuine Zenvorika email will show the code you chose. No code, or the wrong code, means delete the email.

  4. Nobody from Zenvorika will ask for your password or 2FA code

    Not support, not security, not anyone. The same goes for seed phrases of your own wallets.

  5. Bookmark the site

    Type zenvorika.com once, bookmark it and use the bookmark. Ads and search results can be spoofed.

  6. Turn on the withdrawal whitelist

    It is the single setting that most limits the damage if someone does get into your account.

Read: Wallet security basics