Security
Bitzlatoview is built around the following security principles:
- Double-entry ledger: every balance change is a matched debit/credit pair — balances are never mutated directly.
- No direct balance edits: admin balance adjustments require a maker/checker approval flow with a documented reason and evidence.
- KYC/AML gates: withdrawals, virtual cards, futures, forex, stock trading and P2P merchant status require an approved identity verification.
- Two-factor authentication: available for login and required for high-risk actions such as withdrawals and security changes.
- Full audit logging: every sensitive admin and user action is logged with actor, IP address, and before/after state.
- Idempotency keys: financial operations use idempotency keys to prevent duplicate processing on retries.
- Withdrawal address whitelisting: new withdrawal addresses go through a cooldown period before first use.
Bitzlatoview does not currently custody real user funds pending completion of licensed custody, banking and compliance partnerships. See our Proof of Reserves page for details once live custody begins.