Security & Privacy Pack
A clear overview of CryptoProcessing’s security posture, custody model, platform controls, privacy measures, and supporting assurance materials for merchant, security, finance, and compliance teams
A clear overview of CryptoProcessing’s security posture, custody model, platform controls, privacy measures, and supporting assurance materials for merchant, security, finance, and compliance teams
CryptoProcessing is a payment gateway that processes digital asset payments for regulated businesses. ISO/IEC 27001 certified. Independently audited every year. Security evidence is available under NDA.
ISO/IEC 27001 by Bureau Veritas. CCSS Level 3 certification for asset security – penetration testing performed by Hacken.
*Audit reports available under NDA
Cold-first custody, multi-signature approvals, and access controls for wallet operations. No commingling of client funds.
| Operating scope | Serving hundreds of merchants across many industries for 11+ years. |
| Payment scope | 20+ cryptocurrencies across various networks and 40+ fiat currencies for bank payouts. |
| Asset security | CryptoProcessing by Coinspaid achieved CCSS Level 3 certification for protection of private keys, wallet management, and transaction approval procedures. |
| Technical controls | Separate sandbox and staging environments for testing before production, HTTPS callback requirements, 2FA flows, IP allowlists, and transaction risk scoring. |
Client funds are placed in segregated cold storage. Hot wallets hold only the operational liquidity needed for live processing. Large movements require multi-signature approval. Asset ownership remains with the user.
Webhooks use HTTPS and signed callbacks. The AML framework covers onboarding checks, beneficial owner review, enhanced due diligence, transaction monitoring, training, and authority cooperation.
Every transaction is screened against two independent blockchain intelligence providers – Chainalysis and Crystal, as well as in-house systems. Suspicious flows are flagged in real time and escalated to our compliance team before settlement.
Our custody model is built around a single principle: we limit hot-wallet exposure and move excess balances to cold storage.
ISO/IEC 27001
CCSS v9 Level III
Secure encryption
2FA on key settings
IP whitelisting
HTTPS callbacks
Risk scoring
Data masking
Full policies and audit evidence are available on request. Some materials may require an NDA.
Information Security Management System certificates covering 2 registered entities (Estonia & Lithuania).
Key management and wallet controls covering access, approvals, backups, and risk management. Recognized by the CryptoCurrency Certification Consortium (C4).
Money Services Business registration for Dream Finance Processing Inc.
Reg. N300000209
Communication-channel encryption, encryption at rest, access management, anti-malware, vulnerability fixing, application security tests, and data masking.
Money Services Business registration for Dream Finance US LLC, operating under Bank Secrecy Act obligations.
Reg. 31000313808665
OWASP Web Application Security Testing Guideline. Manual plus automated testing, business logic validation, authorization checks.
Letter available under NDA.
Data handling for merchants, end-users, and site visitors. DPA available to customers on request.
A client-facing view of platform controls. Sensitive internal records can be found in the full diligence set available on request.
Data is encrypted in transit and at rest. PII and wallet metadata is encrypted using documented encryption standards. Secrets and keys are managed through dedicated key management systems and strict access controls.
Role-based access (RBAC) across every internal system. Mandatory multi-factor authentication for employees. Least-privilege by default, with access rights reviewed on a schedule documented in our ISMS.
Security checks are built into development, code review, testing, and release. Critical components are reviewed under OWASP methodology as part of the annual pentest scope.
24/7 security operations with real-time monitoring of platform, wallet infrastructure, and on-chain flows. Our team reviews alerts in-house and checks unusual activity against Chainalysis and Crystal.
We use DDoS protection, scalable payment endpoints, and tested failover. Status communicated through our public status page during any degradation.
Subprocessors are assessed before onboarding and reviewed annually. A current subprocessor list is maintained and delivered with every signed DPA.
Our AML policies cover Travel Rule requirements and local rules in the jurisdictions we serve.
We process personal data as a controller, and – in merchant flows – as a processor on behalf of our clients. Our practices are governed by our Privacy Notice and, for merchant relationships, a DPA available on request.
Lawful basis
Contractual necessity, legal obligation (including AML/CFT), legitimate interest, and explicit consent where required – in line with Article 6 GDPR.
Data residency
Personal and transactional data processed within the EU/EEA. Cross-border transfers use Standard Contractual Clauses and supplementary measures.
Retention
We retain personal data for up to five years after the contract ends, unless the law requires longer.
Data subject rights
Access, rectification, erasure, restriction, portability, and objection handled within statutory deadlines. Requests routed to [email protected].
We build for resilience: redundant systems, a rehearsed response team, and direct updates to any affected merchant.
Production systems run with redundancy across infrastructure layers. Target availability and historical uptime are reported in the Security Pack and on our public status page.
Geographically redundant backups with defined RPO and RTO targets. Disaster recovery procedures are part of a defined protocol.
A documented IR policy covers detection, triage, containment, eradication, recovery, and post-mortem. Affected merchants are notified without delay, with a written root-cause follow-up.
BCP and DR plans are reviewed and tested annually as part of our ISO/IEC 27001 programme. Regulator notification obligations are mapped into the playbooks.
Report a vulnerability
Found a security issue? We’d rather hear from you than anyone else. CryptoProcessing does not intend to pursue legal action against researchers acting in good faith and in accordance with the vulnerability disclosure policy.
Contact: [email protected]
Ack SLA: within 2 business days
PGP key: published at /security
Safe-harbour: applies to good-faith researchers who follow the disclosure policy.
| Available immediately: |
|
| Available under NDA: |
|
Dream Finance OÜ holds ISO/IEC 27001:2022 for providing a virtual currency service. Dream Finance UAB holds an ISO/IEC 27001:2022 certificate for the provision of cryptocurrency service. The platform holds a CCSS Level 3 certification for protection of private keys, wallet management, and transaction approval procedures – conducted by Hacken in 2025-2026. Further audit and penetration testing evidence is available under NDA.
Client funds are held using a cold-first custody model. The majority of assets are kept offline, while hot wallets hold only the liquidity required for live processing. Large movements require multi-signature approval, and client funds are separated from any company operating capital.
Merchants can define maximum operational balance thresholds. Amounts above those thresholds can be automatically swept into cold storage, reducing unnecessary exposure in hot-wallet infrastructure.
We monitor transactions in real time and after settlement. Alerts come from our own systems and from external providers, including Crystal and Chainalysis. In-house rules flag unusual patterns and behavior.
Merchants are verified during onboarding through KYB checks covering identity, beneficial ownership, sanctions exposure, and risk profile. High-risk profiles may require Enhanced Due Diligence.
Personal data is processed in line with GDPR. In merchant flows, CryptoProcessing may act as a processor on behalf of clients, with a Data Processing Agreement available on request. Personal and transactional data is processed within the EU/EEA, and cross-border transfers use Standard Contractual Clauses and supplementary safeguards where required.
Personal data is retained for a maximum of five years after the end of the contractual relationship, unless a longer retention period is required by law, including AML/CFT obligations.
Controls include encryption in transit and at rest, cryptographic protection for sensitive data, role-based access control, mandatory multi-factor authentication, IP whitelisting, security monitoring, and annual penetration testing.
CryptoProcessing maintains a documented incident response policy covering detection, triage, containment, eradication, recovery, and post-mortem review. Affected merchants are notified without delay, followed by written root-cause information where applicable.
Production systems are built with redundancy across infrastructure layers. Backups are encrypted and geographically redundant, with defined recovery point and recovery time objectives. Business continuity and disaster recovery plans are reviewed and tested annually as part of the ISO/IEC 27001 programme.
Yes. The Security Pack includes immediately available materials such as the ISO/IEC 27001 certificates, pentest executive letters, custody architecture whitepaper, subprocessor list, and Privacy Notice. Additional materials, including full pentest reports, the Statement of Applicability, incident response plans, BCP/DR plans, the Master DPA, and an extended control matrix, are available under NDA.
Security issues can be reported to [email protected]. Good-faith researchers acting under its policy are protected by safe-harbour terms, with acknowledgement targeted within two business days.
This document is an informational overview prepared by CryptoProcessing by Coinspaid for clients, counterparties, and their security, finance, and compliance teams.
Fill out the form and we’ll reach out.
Know businesses that want to accept crypto? Refer them and earn passive income through our partner program.
Fill out the form and we’ll reach out.