Security Policies

Security of funds and user information is our top priority. Our security team is continually improving our end-to-end security measures, improving auditing processes, and reducing the 'attack surface' of our infrastructure. Please note that we cannot disclose too many details of the security measures implemented on the platform for security and proprietary reasons.

User Account Protection

Some of the security measures highlighted below are in place by default, and others can be activated based on the security level you need. Please visit to check the security status of your account and see recommendations.


Two-factor authentication (2FA)

Add an extra layer of security to your account and protect sensitive operations such as logging in, generating API keys, and withdrawing. Configure two-factor authentication using Google Authenticator, or OTP Security Key.


Advanced verification tools to monitor the integrity of your account

  • Login data is saved and analyzed for unusual activity.
  • Intelligent system detects IP Address changes to prevent session hijacking.
  • Email notifications report logins and include a link to instantly freeze your account if you suspect malicious activity.
  • Limit access to your account based on IP address.

Withdrawals protection

  • Security system monitors withdrawals by IP address and other user behavior patterns, triggering manual admin inspection on withdrawals that appear unusual.
  • Withdrawal confirmation step that is immune to malicious browser malware.
  • Define an address whitelist to ensure no withdrawals can go anywhere else.


Cryptocurrency Storage

The overwhelming majority of system funds are stored in offline, cold wallets. Only approximately 0.5% of crypto assets are accessible in hot wallets for day-to-day platform operations. As an added protection, the cold wallets are not available from the platform or the platform servers. The funds in offline cold storage require manual intervention by several members of our management to access.

System Security

Always up-to-date Linux systems to host the platform

Our server’s network is protected using always up-to-date software and the best possible practices.


Automatic backup of the database once a day

Once a day, the database of the platform is backed up, encrypted and compressed as an archive.


Duplication of backup data automatically

As soon as a new backup is ready (database, log files,), it is sent to others servers in several physical locations.


Protection from DDoS attacks

We are protected by automatic Distributed Denial of Service protection to ensure that trading cannot be halted by outside attacks.

Securing your account - Tips & Best Practices

Keeping your account and funds safe is always our top most priority. You form an important part of the effort and together we can keep as the most secure exchange. Below are some important best practices you should follow to keep your account secure.

 Using the right 

  • If you are trading via the website, ensure the domain is
  • When you receive emails from, check if the email ID is


  • Always Set a strong password for your account
  • Passwords must be atleast 6 characters long and a maximum of 64 characters. We recommend using passwords longer than 10 characters.
  • Include a combination of characters, numbers and symbols like $%^~ in your password
  • Never use common words as passwords. For eg your name or birthdate or your pet's name
  • Never use a password that you have used elsewhere. For eg - your email password, your facebook password or even your password for another cryptocurrency exchange
  • Never share your password with anyone else. will never call or email you asking for your password. Nobody needs your password to help you with a problem.

You should also follow the above tips to secure the email ID that you have registered with your account.


  • Never share your OTP with anyone else. Even if someone claims they're contacting your from We never need your OTP to help you with any problem.
  • If you have received an OTP on your phone without requesting for one, please contact our support team immediately.  

Account Details

  • Never share account details like your registered email ID, mobile number, bank details, and Transaction number or amount publicly. Only share it with the support team if asked through official Support Ticket System within your account.


  • Keep your phone OS updated to the latest version. Your OS makes regular security updates so it's important that you stay updated with the latest fixes.
  • Setup fingerprint recognition, passcode or any other access security features that you phone may support
  • If possible, enable features that wipe out your phone in case it is lost.
  • Avoid jailbreaking your phone as that may compromise the phone's security updates.
  • Install a good antivirus software on your computer but don't depend entirely on it.
  • Avoid installing too many softwares or browser extensions.
  • Do not download or install files you don't trust. Especially if they download automatically or are sent as an email attachment
  • Only connect to WIFI & Internet networks that you are familiar with and fully trust. Keep your home WIFI networks password protected

Crypto Deposits & Withdrawals

  • Always cross check the deposit address that you have copied when you paste it into the withdrawal wallet. 

General Advice

  • Avoid operating your account on public computers like cyber cafes
  • Always log out of your account if someone else uses the same device
  • Avoid sharing details of your investments in public channels like telegram, whatsapp, forums etc. Don't disclose your cryptocurrency holdings to anyone in public.
  • Never send money to anyone claiming to be representing We will never ask you to send money to random addresses or accounts
  • Setup 2FA for the email ID that you use for trading. For eg - Gmail, Outlook etc

Official TradeXic Accounts/Links

The following are official accounts on social media and other platforms. We advise you to please not interact with any other accounts.

Note: Avoid any request claiming company person or partner asking for money or account informatins by email, sms or call, we only send and receive account realated requests by our platforms in built support ticket system.