How we protect your money, your assets and your data.
The specifics, including the parts most providers leave out. Every claim on this page maps to a control you can ask us about.
Your account
Two-factor authentication
Required on login and again on every withdrawal. Turning it off triggers a high-severity alert to your registered contacts.
Device and session visibility
See which devices are signed in, end any session, and get an alert whenever a new device or location is used.
Password standards
Minimum length enforced and known-breached passwords rejected at the point of entry.
Moving money out
Withdrawal address whitelisting
Digital assets leave only to addresses you have approved in advance, with a cooling-off period on newly added addresses.
Confirmation on every withdrawal
Second-factor confirmation on each withdrawal and each new recipient, not just at login.
Velocity limits
Limits on how much can move in a period, sized to your account, so a compromised session cannot drain a balance in one go.
How assets are held
MPC custody
Digital assets are held in multi-party computation custody with policy controls, so no single key and no single person can move funds alone.
Segregated currency balances
Customer currency balances are held with regulated financial partners, separately from our own operating funds. We do not lend customer balances out.
One ledger of record
Every balance and movement is recorded in the core ledger and reconciled daily against the funds held at our providers.
The platform
Encryption
Data encrypted in transit and at rest, with keys managed separately from the systems that use them.
Least-privilege access
Internal access is role-based, granted on a documented request, reviewed regularly and revoked the day someone leaves.
Audit logging
Privileged actions are logged and reviewed. Logs are retained in line with our record-keeping obligations.
Independent testing
The platform is penetration tested by an external party, and findings are tracked to closure.
Language we avoid
We will not tell you we are unhackable.
No system is one hundred percent secure, and any provider that says otherwise is telling you something they cannot support. What we can do is name the controls, keep them current, and have them tested by people who do not work here.
Are my funds insured?
Digital assets are not covered by deposit insurance, and Nomos Pay is not a bank. What protects your balance is the custody model, the segregation of customer funds from our own, and the controls described on this page. If you need a specific written position on protection for a procurement or audit process, ask us and we will give you one.
What will you never ask me for?
We will never ask for your password, a two-factor code, or a seed phrase, and we will never ask you to move funds to a "safe" address. Anyone doing so is not us. Our official domains and channels are listed on the approved channels page.
How do I report a security issue?
Email security@nomospay.com with the details. We will acknowledge it, investigate, and keep you informed. We do not take legal action against researchers who report issues in good faith and do not access data belonging to other people.
What happens if you detect something suspicious on my account?
Depending on what it is, we may ask you to confirm a transaction, temporarily restrict an action, or contact you directly. Where we are able to explain the reason we will. In some cases the law limits what we are permitted to tell you.
Questions your security team needs answered? in one place?
Send them over. We would rather have the conversation before you open an account than after.