SECURITY001 — Security overview

Last updated: September 1, 2026

Security is paramount when dealing with financial transactions and payments. For over 14 years, Xtrm has developed and implemented a range of advanced, integrated security measures to ensure system integrity and data protection.

Password protection

  • Complex password access. All user access requires complex passwords with a minimum of 8 characters, including numbers and special characters.

  • SHA encryption with salt. All passwords are securely stored using SHA encryption with salting, making them unrecoverable.

Access controls

  • Access lockout. Multiple failed login attempts result in account lockout and are logged for security monitoring.

  • IP-based access. IP-specific restrictions can be implemented for controlled and secure access.

  • Location-based access. Geographic restrictions can be applied for an additional layer of protection.

  • One-time passwords (2-step authentication). OTPs are used for added security, with validation based on both device and IP.

  • CAPTCHA protection. CAPTCHA technology is in place to prevent automated attacks and ensure that only legitimate users gain access.

Role and activity monitoring

  • Advanced role-based access. Multi-tiered, role-specific access allows for granular user permission control across teams and departments.

  • Real-time KYC validation (Know Your Customer). Immediate verification of individuals and companies during onboarding and payment transactions.

  • Real-time AML validation (Anti-Money Laundering). Instant checks on all payment activity to detect and prevent suspicious transactions.

Data and network security

  • Secure, encrypted data. All data is encrypted both at rest and in transit using state-of-the-art methods. Detailed specifications are available upon request.

  • Regular independent site scans. Third-party vulnerability scans (static and dynamic) are conducted regularly, using providers such as Veracode and Trustwave.

  • Firewall protection. Enterprise-grade firewall systems guard against unauthorized access.

  • Web Application Firewall (WAF). Protection against DoS/DDoS attacks, spam bots, and SQL injection threats.

  • Physically secure servers. All servers are housed in highly restricted facilities with secure passkey access and monitoring.

Compliance and policies

  • SOC1 and SOC2 compliant. Certification documentation available upon request.

  • PCI compliant. Subject to regular external vulnerability assessments.

  • Security policies. Formal, documented security policies are in place and regularly reviewed.