KYC & AML Screening
Every user is identity-verified before placing orders. All crypto addresses and transactions are screened against AML risk databases to block fraudulent activity.
Protecting your funds and personal data is our top priority. Here's how we secure the platform and how you can protect yourself.
Every user is identity-verified before placing orders. All crypto addresses and transactions are screened against AML risk databases to block fraudulent activity.
All data in transit is encrypted with TLS 1.3. Sensitive data at rest is encrypted using AES-256. We never store card numbers — payments are handled by PCI-DSS compliant processors.
We never hold your crypto. Coins go directly from our liquidity to your wallet on-chain. There is no Xbit wallet to hack — your assets stay in your control.
We use Clerk for authentication, providing industry-standard JWT sessions, device tracking, and optional multi-factor authentication (MFA).
All inbound payment webhooks are verified using HMAC signatures. We validate every callback before processing to prevent spoofed payment notifications.
All API endpoints are rate-limited to protect against brute-force attacks, credential stuffing, and denial-of-service attempts.
Xbit will never ask for your password, private keys, or seed phrase via email, chat, or phone. If you receive a suspicious message claiming to be from Xbit, do not click any links and report it to security@xbit.ge immediately. Always check that you are on xbit.ge before logging in.