Live environment — real market prices, 24/7
2021 Zero security incident since 2021

Your assets, protected
at every layer.

When you credit your NexoBot account, you hand us real value — and we treat that as a duty, not a feature. Ninety-five percent cold storage. Withdrawals locked to your whitelist. Mandatory 2FA. Encryption everywhere. Nothing less.

Create your account

No commitment · Cancel anytime

95% cold storageMandatory 2FAAES-256 at restTLS 1.3 in transit
Custody status
Live — 24/7
Cold storage allocation95%
  • Two-factor authenticationEnforced
  • Withdrawal whitelistActive
  • Hot wallet signingMulti-sig 3-of-5
  • Last infrastructure scanQ2 2026 — clean
95%
Assets in cold storage
0
Security incidents since 2021
99.97%
Platform uptime
24/7
Monitoring & on-call

Figures describe the production security model, reviewed continuously.

Custody model

How your assets are held

NexoBot is a custodial platform: your wallet is funded on NexoBot and bots trade directly from your account. That model only works if custody is engineered conservatively.

Segregated client assets

Client balances are accounted separately from company funds, with daily reconciliation across every wallet.

Multi-signature cold storage

Cold keys are split across hardware devices, geographies and people. No single person — employee or founder — can move funds alone.

Minimal hot exposure

Only ~5% of assets stay online, sized to cover typical daily withdrawals with comfortable headroom.

Cold / hot allocation

  • Cold storage — offline, multi-sig95%
  • Hot wallet — withdrawal liquidity5%

Proportion of client assets by storage type.

Layered controls

Defense in depth, on by default

Every control below ships enabled on every account. No toggles, no paid add-ons, no opt-outs.

Account change locks

Password, 2FA or whitelist changes lock withdrawals for 24 hours. An attacker can't quietly burn the trail.

Whitelisted withdrawals

Funds can only leave to addresses you approved in advance. New addresses face a 24-hour cooling-off period.

Mandatory 2FA

TOTP two-factor is enforced for login, withdrawals and security changes — there is no opt-out.

AES-256 at rest

Sensitive data — wallet metadata, credentials, personal records — is encrypted with AES-256.

TLS 1.3 in transit

All traffic to NexoBot is encrypted with TLS 1.3. HSTS is enforced and plaintext connections are refused.

24/7 monitoring

Anomaly detection runs on every request and every movement of funds. On-call engineers answer critical alerts around the clock.

Device & session control

See every active session, revoke a device remotely and sign out everywhere from your settings.

Hardened infrastructure

Least-privilege access, segregated environments, rate limiting and DDoS mitigation at the edge.

Withdrawal process

Five gates stand between your funds and an attacker

A legitimate withdrawal takes minutes to request and clears within hours. Every gate below runs automatically.

  1. 01

    Request

    Enter the amount and pick a destination from your dashboard. Recent password or 2FA changes keep withdrawals locked for 24 hours.

  2. 02

    2FA confirmation

    A fresh TOTP code confirms the request. A first-time device also triggers an email verification.

  3. 03

    Whitelist check

    The destination must already be on your approved list. Any new address waits out a mandatory cooling-off period.

  4. 04

    Risk review

    Withdrawals that are unusually large or irregular are held for manual review by our operations team.

  5. 05

    Signed & released

    Approved payouts are signed from the hot wallet and broadcast on-chain. You get a confirmation with the transaction hash.

Typical processing time: under 2 hours. Cooling-off on new addresses: 24 hours.

Compliance

Audited, documented, honest about it

Trust is earned with evidence. Here is exactly where we stand — including what is still in progress.

Assessment in progress

SOC 2 Type II

An external auditor is evaluating our security, availability and confidentiality controls. The report is published once granted.

Compliant

GDPR

Personal data is processed in line with the EU General Data Protection Regulation, with a named data protection contact.

Completed Q2 2026

Penetration testing

Independent offensive security audit every year. Findings are triaged and remediated under a strict internal SLA.

We only display certifications we actually hold. Anything still being assessed is labelled 'in progress'.

FAQ

Security, answered

Yes — that is what a custodial platform means: bots trade from your NexoBot account. Moving funds out, however, requires your 2FA and a pre-approved address, and internal wallet access is restricted by multi-signature controls.

Hold your capital to a higher standard.

Create your account and inspect the platform yourself — the demo wallet starts with 10,000 virtual USDT.

Create your account

No commitment · Cancel anytime

Security & Asset Custody — NexoBot · NexoBot