🔐TLS Between Services
External endpoints terminate TLS 1.3 at Cloudflare. Internally, the resource platform reaches the signer over mutual TLS with full certificate verification; the wallet bot presents a client certificate but does not yet verify the signer's certificate, and the TRON broadcaster is reached over plain HTTP on a private Docker network. We do not do certificate pinning. Closing the two remaining gaps is tracked work.
🔑PBKDF2 Encryption At Rest
Deposit-address private keys are stored encrypted in our PostgreSQL database, not in a key vault. They are encrypted with Fernet (AES-128-CBC plus HMAC-SHA256) under a key derived by PBKDF2-HMAC-SHA256. Keys are currently written at 600,000 iterations; keys written under earlier parameters stay readable, because we retain every past derivation setting permanently rather than leave stored data undecryptable. The master key that derivation starts from is held in AWS Secrets Manager under IAM policy and delivered to containers in memory at start-up. Hot-wallet keys are held by the signer service, sourced from the same Secrets Manager store.
✅Approval Workflow
Two operators must approve any withdrawal above $100. That is the threshold at the verification tier every account is on today. Verification would raise it -- to at most 10,000 USDT equivalent for a fully verified account. Until an account completes E-Gates PassMe verification, $100 is the figure that applies. The platform refuses to start if it is configured in a way that would let one person satisfy the requirement. Every withdrawal is scored by a risk engine before signing, and flagged withdrawals wait for a human.
🚫Outflow Ceilings
Two ceilings cap what can leave the platform: $5,000 on any single withdrawal and $10,000 from any one account in 24 hours. These are limits we enforce against abuse, not allowances we grant. They apply to every account and are not lifted by verification.
🛡️Isolated Signer Service
Hot-wallet signing runs in a separate signer container on its own network segment, with no outbound network access and a bearer token on every request; application services never see hot-wallet key material. Sweeps from individual deposit addresses are the exception: the wallet service decrypts that address's own private key inside its own process. On TRON the decrypted key is then handed to the signer, which builds and signs; on every other chain the wallet service signs locally. Moving deposit sweeps behind the signer is tracked work.
📝Tamper-Evident Audit Log
Every custody action is written to a SHA-256 hash-chained audit log in PostgreSQL: each entry commits to the previous entry's hash and to a hash of its own payload. A verifier walks the chain every hour and alerts on any edited, deleted or inserted row. This detects tampering rather than preventing it -- entries are not yet written to write-once storage, so an operator with database access can still delete a row, and the chain will show that they did.
🔍Real-Time Monitoring
Infrastructure monitoring via Prometheus, Grafana, and Loki, with automated alerting on anomalous transactions, reconciliation shortfalls, and system health. Operational log retention is 72 hours; the audit log in PostgreSQL is separate and is not on that clock.
🌐Network Segmentation
Services run in isolated Docker containers with dedicated internal networks. Database access is restricted to services that require it, and the signer has no route to the public internet.