Cryptoprocessing | Security & Privacy pack

Security & Privacy Pack

A clear overview of CryptoProcessing’s security posture, custody model, platform controls, privacy measures, and supporting assurance materials for merchant, security, finance, and compliance teams

ISO/IEC 27001:2022 certified
CCSS Level III asset security
Cold-first custody architecture
Platform controls
Cryptoprocessing | Security & Privacy pack
Cryptoprocessing | Security & Privacy pack
Cryptoprocessing | Security & Privacy pack
Cryptoprocessing | Security & Privacy pack
Cryptoprocessing | Security & Privacy pack
+ 20 more
supported cryptocurrencies
Cryptoprocessing | Security & Privacy pack
Security posture
Cryptoprocessing | Security & Privacy pack
Custody
Cryptoprocessing | Security & Privacy pack
Privacy
Cryptoprocessing | Security & Privacy pack
Certifications
Cryptoprocessing | Security & Privacy pack
Proof pack
Table of Contents:

11+ years of secure transactions

CryptoProcessing is a payment gateway that processes digital asset payments for regulated businesses. ISO/IEC 27001 certified. Independently audited every year. Security evidence is available under NDA.

Audited

ISO/IEC 27001 by Bureau Veritas. CCSS Level 3 certification for asset security – penetration testing performed by Hacken.

*Audit reports available under NDA

Architecture

Cold-first custody, multi-signature approvals, and access controls for wallet operations. No commingling of client funds.

What you’ll find in this pack

Cryptoprocessing | Security & Privacy pack
Security posture and ownership of risk
Cryptoprocessing | Security & Privacy pack
Custody and settlement architecture
Cryptoprocessing | Security & Privacy pack
Certifications, audits, and review details

Security posture at a glance

Operating scope Serving hundreds of merchants across many industries for 11+ years.
Payment scope 20+ cryptocurrencies across various networks and 40+ fiat currencies for bank payouts.
Asset security CryptoProcessing by Coinspaid achieved CCSS Level 3 certification for protection of private keys, wallet management, and transaction approval procedures.
Technical controls Separate sandbox and staging environments for testing before production, HTTPS callback requirements, 2FA flows, IP allowlists, and transaction risk scoring.
Product docs Legal Pack ISO certificate CCSS announcement Integration checklist Authorization Callbacks
Cryptoprocessing | Security & Privacy pack
Cold-first
architecture

Client funds are placed in segregated cold storage. Hot wallets hold only the operational liquidity needed for live processing. Large movements require multi-signature approval. Asset ownership remains with the user.

Cryptoprocessing | Security & Privacy pack
Established controls & policies

Webhooks use HTTPS and signed callbacks. The AML framework covers onboarding checks, beneficial owner review, enhanced due diligence, transaction monitoring, training, and authority cooperation.

Cryptoprocessing | Security & Privacy pack
On-chain
analytics

Every transaction is screened against two independent blockchain intelligence providers – Chainalysis and Crystal, as well as in-house systems. Suspicious flows are flagged in real time and escalated to our compliance team before settlement.

How we protect client funds

Our custody model is built around a single principle: we limit hot-wallet exposure and move excess balances to cold storage.

Custody controls

  • Cold storage by default
    Most client assets are held offline, segregated from hot wallets servicing live flows.
  • Configurable thresholds
    Merchants define the maximum operational balance; excess is swept automatically to cold storage.
  • Multi-signature approvals
    Withdrawals from cold storage require multiple independent signers with enforced separation of duties.
  • Fiat settlement
    Merchants can settle crypto payments to fiat bank payouts instead of holding crypto.
  • No rolling reserves
    Virtual assets remain the user’s property and can be withdrawn under the Terms of Use.
Terms of use AML policy https://docs.cryptoprocessing.com/integration-guide/api-set-up-stage Authorization Callbacks API key setup Transaction tracking

Security controls available for review

ISO/IEC 27001

CCSS v9 Level III

Secure encryption

2FA on key settings

IP whitelisting

HTTPS callbacks

Risk scoring

Data masking

Certifications, registrations & controls

Full policies and audit evidence are available on request. Some materials may require an NDA.

Cryptoprocessing | Security & Privacy pack
ISO/IEC 27001:2022
Bureau Veritas; Swiss Approval North America
Active

Information Security Management System certificates covering 2 registered entities (Estonia & Lithuania).

Cryptoprocessing | Security & Privacy pack
CCSS Level 3
Hacken
Active

Key management and wallet controls covering access, approvals, backups, and risk management. Recognized by the CryptoCurrency Certification Consortium (C4).

Cryptoprocessing | Security & Privacy pack
MSB registration - Canada
FINTRAC
Active

Money Services Business registration for Dream Finance Processing Inc.
Reg. N300000209

Cryptoprocessing | Security & Privacy pack
Privacy security measures
Established data protection policies
Active

Communication-channel encryption, encryption at rest, access management, anti-malware, vulnerability fixing, application security tests, and data masking.

Cryptoprocessing | Security & Privacy pack
MSB registration - US
FinCEN
Active

Money Services Business registration for Dream Finance US LLC, operating under Bank Secrecy Act obligations.
Reg. 31000313808665

Cryptoprocessing | Security & Privacy pack
Penetration testing
10Guards, Hacken
Annual

OWASP Web Application Security Testing Guideline. Manual plus automated testing, business logic validation, authorization checks.
Letter available under NDA.

Cryptoprocessing | Security & Privacy pack
GDPR compliance
Aligned with Reg. (EU) 2016/679
Active

Data handling for merchants, end-users, and site visitors. DPA available to customers on request.

Application & infrastructure security

A client-facing view of platform controls. Sensitive internal records can be found in the full diligence set available on request.

Encryption

Data is encrypted in transit and at rest. PII and wallet metadata is encrypted using documented encryption standards. Secrets and keys are managed through dedicated key management systems and strict access controls.

Access control

Role-based access (RBAC) across every internal system. Mandatory multi-factor authentication for employees. Least-privilege by default, with access rights reviewed on a schedule documented in our ISMS.

Secure development

Security checks are built into development, code review, testing, and release. Critical components are reviewed under OWASP methodology as part of the annual pentest scope.

Monitoring & detection

24/7 security operations with real-time monitoring of platform, wallet infrastructure, and on-chain flows. Our team reviews alerts in-house and checks unusual activity against Chainalysis and Crystal.

DDoS & availability

We use DDoS protection, scalable payment endpoints, and tested failover. Status communicated through our public status page during any degradation.

Third-party & supply chain

Subprocessors are assessed before onboarding and reviewed annually. A current subprocessor list is maintained and delivered with every signed DPA.

Compliance and reporting

Our AML policies cover Travel Rule requirements and local rules in the jurisdictions we serve.

  • Merchant onboarding (KYB)
    Every merchant is verified at onboarding against identity, beneficial ownership, and sanctions data. High-risk merchants go through Enhanced Due Diligence before activation.
  • End-user KYC
    Where the service model requires user-level identification, KYC is performed against reliable, independent sources in line with EU and national obligations.
  • Continuous transaction monitoring
    Every inbound and outbound transaction is risk-scored in real time. Alerts are reviewed by human analysts in our in-house compliance team.
  • Dual blockchain analytics
    Screening runs against two independent providers – Chainalysis and Crystal – to cross-validate risk and reduce single-vendor blind spots.
  • Sanctions & PEP screening
    Ongoing screening against EU, UN, OFAC, and HMT sanctions lists, plus PEP and adverse-media checks.
  • Governance & reporting
    In-house MLRO and AML officers report to the board. Suspicious activity reporting and regulator engagement are handled internally, not outsourced.

Data protection and retention

We process personal data as a controller, and – in merchant flows – as a processor on behalf of our clients. Our practices are governed by our Privacy Notice and, for merchant relationships, a DPA available on request.

Lawful basis

Contractual necessity, legal obligation (including AML/CFT), legitimate interest, and explicit consent where required – in line with Article 6 GDPR.

Data residency

Personal and transactional data processed within the EU/EEA. Cross-border transfers use Standard Contractual Clauses and supplementary measures.

Retention

We retain personal data for up to five years after the contract ends, unless the law requires longer.

Data subject rights

Access, rectification, erasure, restriction, portability, and objection handled within statutory deadlines. Requests routed to [email protected].

Resilience & incident response

We build for resilience: redundant systems, a rehearsed response team, and direct updates to any affected merchant.

Cryptoprocessing | Security & Privacy pack
Availability

Production systems run with redundancy across infrastructure layers. Target availability and historical uptime are reported in the Security Pack and on our public status page.

Cryptoprocessing | Security & Privacy pack
Backups & disaster recovery

Geographically redundant backups with defined RPO and RTO targets. Disaster recovery procedures are part of a defined protocol.

Cryptoprocessing|Security & Privacy pack
Incident response

A documented IR policy covers detection, triage, containment, eradication, recovery, and post-mortem. Affected merchants are notified without delay, with a written root-cause follow-up.

Cryptoprocessing | Security & Privacy pack
Business continuity

BCP and DR plans are reviewed and tested annually as part of our ISO/IEC 27001 programme. Regulator notification obligations are mapped into the playbooks.

Report a vulnerability

Found a security issue? We’d rather hear from you than anyone else. CryptoProcessing does not intend to pursue legal action against researchers acting in good faith and in accordance with the vulnerability disclosure policy.

Contact: [email protected]
Ack SLA: within 2 business days
PGP key: published at /security
Safe-harbour: applies to good-faith researchers who follow the disclosure policy.

The security pack

Available immediately:
  • ISO/IEC 27001 certificate
  • Pentest executive letters (Hacken, 10Guards)
  • Custody architecture documentation
  • Subprocessor list & Privacy Notice
Available under NDA:
  • Full pentest reports & SoA
  • Incident response & BCP/DR plans
  • Master DPA & extended controls

FAQ

What certifications does CryptoProcessing hold?

Dream Finance OÜ holds ISO/IEC 27001:2022 for providing a virtual currency service. Dream Finance UAB holds an ISO/IEC 27001:2022 certificate for the provision of cryptocurrency service. The platform holds a CCSS Level 3 certification for protection of private keys, wallet management, and transaction approval procedures – conducted by Hacken in 2025-2026. Further audit and penetration testing evidence is available under NDA.

How are client funds protected?

Client funds are held using a cold-first custody model. The majority of assets are kept offline, while hot wallets hold only the liquidity required for live processing. Large movements require multi-signature approval, and client funds are separated from any company operating capital.

Can merchants set custody or balance limits?

Merchants can define maximum operational balance thresholds. Amounts above those thresholds can be automatically swept into cold storage, reducing unnecessary exposure in hot-wallet infrastructure.

How are transactions screened for risk?

We monitor transactions in real time and after settlement. Alerts come from our own systems and from external providers, including Crystal and Chainalysis. In-house rules flag unusual patterns and behavior.

What AML and sanctions controls are applied?

Merchants are verified during onboarding through KYB checks covering identity, beneficial ownership, sanctions exposure, and risk profile. High-risk profiles may require Enhanced Due Diligence.

How is personal data handled?

Personal data is processed in line with GDPR. In merchant flows, CryptoProcessing may act as a processor on behalf of clients, with a Data Processing Agreement available on request. Personal and transactional data is processed within the EU/EEA, and cross-border transfers use Standard Contractual Clauses and supplementary safeguards where required.

How long is data retained?

Personal data is retained for a maximum of five years after the end of the contractual relationship, unless a longer retention period is required by law, including AML/CFT obligations.

What security controls protect the platform?

Controls include encryption in transit and at rest, cryptographic protection for sensitive data, role-based access control, mandatory multi-factor authentication, IP whitelisting, security monitoring, and annual penetration testing.

What happens if there is a security incident?

CryptoProcessing maintains a documented incident response policy covering detection, triage, containment, eradication, recovery, and post-mortem review. Affected merchants are notified without delay, followed by written root-cause information where applicable.

What resilience and recovery measures are in place?

Production systems are built with redundancy across infrastructure layers. Backups are encrypted and geographically redundant, with defined recovery point and recovery time objectives. Business continuity and disaster recovery plans are reviewed and tested annually as part of the ISO/IEC 27001 programme.

Can our security team review supporting evidence?

Yes. The Security Pack includes immediately available materials such as the ISO/IEC 27001 certificates, pentest executive letters, custody architecture whitepaper, subprocessor list, and Privacy Notice. Additional materials, including full pentest reports, the Statement of Applicability, incident response plans, BCP/DR plans, the Master DPA, and an extended control matrix, are available under NDA.

How should vulnerabilities be reported?

Security issues can be reported to [email protected]. Good-faith researchers acting under its policy are protected by safe-harbour terms, with acknowledgement targeted within two business days.

This document is an informational overview prepared by CryptoProcessing by Coinspaid for clients, counterparties, and their security, finance, and compliance teams.