Security is a process, not a badge

No platform can honestly promise “unhackable”. What we can show is the architecture, the controls and the habits — and what we expect from you in return.

Platform controls

Defence in depth

Key management

Spending keys are generated and held offline. Internet-facing systems operate watch-only. Signing requires multi-party, logged ceremonies — no single point of compromise moves funds.

Hardened infrastructure

Least-privilege services, strict content-security policies (no inline scripts anywhere on this site), dependency and image scanning in CI, and secrets kept out of code and history.

Fail-closed operations

Ambiguity halts the operation. A stale node, a failed check or an unverifiable state stops the pipeline rather than letting a guess through.

Monitoring & audit trails

Continuous automated monitoring with durable, append-only audit logs. Every balance change is attributable to an evidenced event.

Account protections

Two-factor authentication, new-device verification, session controls, withdrawal allowlists and velocity limits — on by default where possible.

People & process

Background-checked operators, separation of duties, and the standing rule that no single person can authorise movement of customer assets.

Your side of the contract

Account security we ask of you

  • Enable two-factor authentication the day you open the account — an authenticator app, not SMS.
  • Use a unique, generated password. Password reuse is how most accounts actually fall.
  • Set withdrawal allowlists early, while you are calm — they protect you later, when you might not be.
  • Treat every “support agent” who contacts you first as an attacker. We never ask for passwords, codes or remote access.
  • Bookmark the site. Do not follow links to it from emails, ads or messages.

Responsible disclosure. Found a vulnerability? Report it to security@monetisepay.com. Give us reasonable time to remediate before public disclosure; act in good faith and we will engage in good faith — no legal threats for honest research.

Phishing warning. The only legitimate domain is monetisepay.com. Any other spelling, any other TLD, any “urgent verification” message with a login link — assume hostile and report it.

Risk warning: Crypto-assets are highly volatile and you can lose everything you put in. They are not covered by government deposit-protection schemes. Never invest money you cannot afford to lose. Read our full risk disclosure.