Security

At MinutesCrypto, security is built into the platform at multiple levels. We use a combination of infrastructure protection, application security, account controls, data protection, and ongoing monitoring to help protect your information and crypto-related data.

Account & Access Security

Strong Authentication

MinutesCrypto uses secure token-based authentication to protect access to accounts and APIs.

Multifactor Authentication

Users can enable additional authentication methods to add an extra layer of protection to their MinutesCrypto account.

Two-Factor Authentication (2FA)

2FA adds an additional verification, helping protect your account if your password is compromised.

Passkey Authentication

Passkeys provide secure authentication using WebAuthn/FIDO2 technology, helping protect against credential theft and phishing.

Access Control

Authentication alone does not grant access to all information. MinutesCrypto verifies the authenticated user and the relevant account or entity before allowing access to protected data.

Passwordless Sign-In Options

MinutesCrypto supports sign-in methods beyond traditional email and password authentication. Users can sign up or log in using supported third-party authentication providers, such as Google.

Administrative Access

Administrative and operational interfaces are protected separately from normal application functionality and require authenticated access.

Infrastructure & Application Security

Secure Cloud Environment

MinutesCrypto operates on established cloud infrastructure with security controls across the underlying hosting environment. This provides a protected foundation for our application and customer data.

Protection for Stored Data

Customer information and application databases are protected using encryption when stored. This helps prevent unauthorized access to information at the storage layer.

Secure Data Transmission

Connections between users, applications, and services are protected using modern TLS/SSL encryption. This helps keep information secure while it moves between systems.

HTTPS-Only Access

MinutesCrypto enforces HTTPS across the application, ensuring that users and services communicate through encrypted connections.

Security Testing & Threat Detection

We regularly assess our environment for vulnerabilities and monitor for potential threats. This helps us identify security weaknesses and respond to suspicious activity.

Operational Visibility

Security and infrastructure activity is monitored through system logs and operational signals. This gives our team visibility into unusual behavior and potential service issues.

Resilience & Recovery

Backup capabilities and infrastructure monitoring help protect against data loss and service disruption. These measures also support recovery when unexpected infrastructure failures occur.

Security Incident Management

MinutesCrypto maintains procedures for handling security incidents. When an issue is identified, the process includes investigation, escalation, mitigation, and appropriate communication.

PCI Obligations

All payments made to MinutesCrypto are processed securely through Stripe, our payment partner. MinutesCrypto does not directly handle payment card information, while Stripe maintains the applicable payment security and PCI compliance controls.

Data Protection & Privacy

Read-Only Wallet & Exchange Connections

When connecting a supported wallet or exchange, MinutesCrypto uses read-only access to import the information required for accounting. These connections cannot be used by MinutesCrypto to initiate trades, transfers, or withdrawals.

No Custody of Crypto Assets

MinutesCrypto is an accounting and reporting platform and does not hold or manage your cryptocurrency. Your assets remain in the wallets and exchange accounts that you control.

Sensitive Information Protection

Sensitive values such as authentication tokens, secrets, keys, and OTP-related information are protected from unnecessary exposure in application logs.

Secure Cloud Storage

Production file storage uses Amazon S3. Application secrets and sensitive configuration are managed through environment-based secret management and encrypted application credentials.

Data Deletion

Users can permanently delete their entire MinutesCrypto data using the required security PIN.

Data Privacy

MinutesCrypto does not sell personal information. Information is handled as described in our Privacy Policy and may be shared when necessary to provide services, work with service providers, comply with legal obligations, or protect our users.

Monitoring & Security Operations

Security Monitoring

MinutesCrypto monitors application traffic and security events to help identify unusual or potentially malicious activity. This includes visibility into traffic patterns, security events, challenged requests, blocked requests, and application errors.

Proactive Alerts & Monitoring

We have dedicated alerts for key application processes and security-sensitive activities. These alerts help our team monitor system performance, identify unusual behavior, and respond quickly when an issue requires attention.

Audit & Change Tracking

Important record changes can be tracked through application-level audit and version history. Request IDs also help correlate activity and support security investigations and troubleshooting.

Ongoing Security Reviews

We regularly scan and review our applications on a daily or weekly basis to identify potential security risks and areas for improvement. These ongoing checks help us strengthen our security controls and keep the platform protected as it evolves.

Continuous Security Improvement

Security is an ongoing process at MinutesCrypto. We continuously review authentication, authorization, infrastructure, traffic patterns, and security events to identify opportunities to strengthen the platform.

Third-Party Security Assessments

We use trusted third-party security tools to assess our applications and identify potential vulnerabilities. These assessments provide an additional layer of independent security checks.

Your Role in Security

Security is a shared responsibility. We recommend using a strong, unique password, enabling additional authentication, keeping devices and browsers updated, and never sharing private keys, seed phrases, passwords, or authentication codes.

Report a Security Concern

If you believe you have discovered a security issue or notice unauthorized activity involving your MinutesCrypto account, please create a Support Ticket.

Please provide a clear description of the issue and reproduction steps where applicable. Do not include passwords, private keys, seed phrases, or personal information in your report.