Explore
Crea AI
About Us
RESOURCES

Security

Your money, your assets, and your data are held to the highest standard of protection.

Last updated · June 5, 2026

Crestox operates at the intersection of art, technology, and finance. That means the trust you place in this platform is not abstract — it is financial, legal, and personal. This page explains how we protect you, your investments, and the integrity of the marketplace.


Security Philosophy

Crestox is built on three foundational security principles:

Security by Design Security is not a feature added after the fact. It is embedded into every layer of the platform — from how accounts are created, to how artwork is verified, to how transactions are settled. Every system, workflow, and policy is designed with security as a baseline requirement.

Transparency We believe you have the right to understand how your data is handled, how your assets are protected, and what happens if something goes wrong. This page is part of that commitment.

Compliance Crestox operates within applicable legal and regulatory frameworks. Our security practices are designed not only to protect users but to meet and, where possible, exceed the obligations imposed on regulated financial platforms.


Account Security

Your account is the gateway to your investments. We apply multiple layers of protection to ensure only you can access it.

Password Protection

Multi-Factor Authentication (MFA)

Multi-factor authentication is available to all users and strongly recommended. When enabled, logging in requires both your password and a one-time verification code sent to your registered device or authentication application.

To enable MFA, navigate to My Account → Security → Two-Factor Authentication.

Crestox may require MFA for certain high-value transactions or account changes, regardless of your account settings.

Session Management

Device Monitoring

Crestox monitors login activity for signs of unauthorised access, including logins from unrecognised devices or unusual geographic locations. If a login attempt is flagged as suspicious, we will send a security alert to your registered email address.

If you receive a security alert for activity you did not initiate, follow the instructions in the alert immediately and contact our security team.


Data Security

Encryption

All data transmitted between your device and the Crestox platform is encrypted using TLS 1.2 or higher. This applies to all platform interactions, including account access, payments, and document uploads.

Sensitive data stored on our systems — including financial records and identity documents — is encrypted at rest using AES-256 encryption.

Secure Storage

User data is stored on secured infrastructure with access controls that restrict access to authorised personnel only. Our storage systems are subject to regular security review.

Identity documents submitted for KYC verification are stored separately from general platform data and are subject to enhanced access controls.

Access Controls

Internal access to user data is governed by the principle of least privilege: Crestox staff are only granted access to the data they require to perform their specific function. All internal access is logged and subject to audit.

No Crestox employee has standing access to financial credentials, payment card data, or authentication secrets.

Data Retention

We retain your personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law.

Upon account closure, personal data is handled in accordance with our Privacy Policy. Certain transaction and compliance records may be retained for the periods required under financial regulation, even after account closure.

For a full description of how your data is collected, stored, and used, please refer to our Privacy Policy.


Financial Security

Payment Gateway Partners

Crestox does not store payment card data on its own systems. All card transactions are processed through regulated, PCI-DSS compliant payment gateway partners. Your card details are transmitted directly to the payment processor and are never passed through or stored by Crestox.

Bank transfer details provided for wallet withdrawals are encrypted and stored securely, and are used solely for the purpose of processing your withdrawal.

Transaction Auditing

Every transaction on the Crestox platform — including fractal purchases, secondary market sales, wallet deposits, and withdrawals — generates an immutable audit record. These records are retained in accordance with applicable financial regulation and are available to authorised regulators upon request.

You may review your own transaction history at any time under My Account → Transaction History.

Fraud Detection

Crestox operates automated fraud detection systems that monitor transaction activity for patterns associated with fraudulent behaviour. Flagged transactions may be held for review before being processed.

If a transaction is held for review, you will be notified by email. Crestox may request additional verification before releasing a held transaction.

If you believe you have been the victim of fraud involving your Crestox account, contact security@crestox.com immediately. Do not attempt further transactions until the matter is resolved.


Artwork Security

The integrity of what is listed on Crestox is foundational to the value of every fractal on the platform. We apply rigorous controls to ensure that only verified, legitimate artworks are listed.

Artwork Verification

Every artwork submitted to Crestox is reviewed by our internal team before it is approved for listing. This review includes:

Artworks that cannot be verified to the required standard are rejected. This is not a formality — it is how Crestox maintains marketplace credibility.

Ownership Verification

Before an artwork can be fractionalized and listed, the submitting party — whether an artist, curator, or owner — must complete identity verification and, where applicable, provide documentation establishing their right to list the artwork.

Curators are additionally required to provide written authorisation from the relevant artist before any listings may be managed on that artist's behalf.

Approval Workflow

No artwork, artist profile, achievement record, or historical sale is made publicly visible on the platform without passing through the Crestox approval process. This applies without exception. The curated nature of the platform is not a marketing claim — it is a structural safeguard.


Marketplace Integrity

The Crestox secondary marketplace is designed to be transparent and fair. We actively monitor marketplace activity to detect and prevent manipulation.

Anti-Manipulation Controls

The platform applies controls to prevent common forms of marketplace manipulation, including wash trading (a user buying and selling their own fractals to create artificial price movement) and coordinated listing behaviour designed to inflate or deflate perceived value.

Accounts found to be engaging in manipulative behaviour will be suspended and may be reported to relevant regulatory authorities.

Suspicious Trading Detection

Automated systems monitor trading activity across the marketplace for patterns that suggest coordinated manipulation, insider activity, or other forms of market abuse. Flagged activity is reviewed by the Crestox compliance team.

Where suspicious activity is confirmed, Crestox will take appropriate action, which may include transaction reversal, account suspension, and regulatory notification.

Listing Review Systems

All primary artwork listings undergo the approval process described in Artwork Security above. Secondary listings (fractal resales by collectors) are subject to automated screening and may be reviewed manually where activity is flagged as unusual.


Vulnerability Reporting

Responsible Disclosure Policy

Crestox welcomes good-faith security research. If you discover a vulnerability in our platform, we ask that you report it to us privately and responsibly before disclosing it publicly, so that we have the opportunity to investigate and remediate the issue before it can be exploited.

What to report:

How to report:

Send your report to security@crestox.com with the subject line "Responsible Disclosure — [Brief Description]".

Your report should include:

What you can expect from us:

Stage Commitment
Acknowledgement Within 3 business days of receipt
Initial Assessment Within 7 business days of acknowledgement
Resolution Update Within 30 business days, or sooner where possible

We will not pursue legal action against researchers who report vulnerabilities in good faith in accordance with this policy, provided they do not access, modify, or delete user data beyond what is necessary to demonstrate the vulnerability, and do not disclose the vulnerability publicly before we have had a reasonable opportunity to address it.

Crestox does not currently operate a paid bug bounty programme. This may change in the future and will be communicated on this page.


Incident Response

In the event of a security incident, Crestox follows a structured response process designed to contain the impact, notify affected parties, and restore normal operations as quickly as possible.

Detection

Crestox operates continuous monitoring of its systems and infrastructure. Security alerts are reviewed by our team around the clock. Anomalies that may indicate a breach or attack are escalated immediately for investigation.

Containment

Upon confirming a security incident, our first priority is containment — isolating affected systems to prevent further exposure while preserving evidence needed for investigation.

Notification

Affected users: Where a security incident results in the unauthorised access to, or disclosure of, personal data, Crestox will notify affected users as soon as reasonably practicable after the incident is confirmed. Notification will be sent to your registered email address and will include a description of what occurred, what data was affected, and what steps you should take.

Regulatory notification: Crestox will notify relevant regulatory authorities in accordance with applicable data protection and financial regulation. Where required by law, notification will be made within the prescribed timeframe (typically 72 hours of confirming a personal data breach under applicable data protection law).

What we will never do: Crestox will not delay notifying users in order to minimise reputational impact, and will not issue notification that downplays the severity of a confirmed incident.

Recovery

Following containment, Crestox will conduct a full post-incident review to identify the root cause, remediate the vulnerability, and implement controls to prevent recurrence. A summary of findings and remediation steps will be published where appropriate and proportionate to do so.


Compliance & Certifications

Current Registrations

Crestox operates as a duly incorporated entity and maintains all registrations required to conduct its business activities under applicable law, including:

Specific registration details are available upon request to compliance@crestox.com.

Future Certifications & Audits

Crestox is actively working toward the following:

Milestone Status
ISO/IEC 27001 (Information Security Management) In progress
Independent security audit by accredited third party Planned
PCI-DSS assessment (platform-level) Planned
Formal AML/KYC compliance programme review Planned

This page will be updated as certifications and audit results are obtained. We will not claim certifications we have not received.


Privacy Commitments

Crestox collects and processes personal data solely for the purposes necessary to operate the platform, comply with applicable law, and protect the security of users and the marketplace.

We do not sell your personal data to third parties. We do not use your data for purposes unrelated to your use of the platform without your explicit consent.

Your rights in relation to your personal data — including rights of access, correction, deletion, and portability where applicable — are set out in our Privacy Policy.

For privacy-related enquiries, contact privacy@crestox.com.


Security Contact

For all security-related communications:

Purpose Contact
Vulnerability reporting security@crestox.com
Suspected account compromise security@crestox.com
Privacy enquiries privacy@crestox.com
Compliance & regulatory enquiries compliance@crestox.com

In the event of an urgent security concern — including a suspected account breach or active fraud — please contact us at security@crestox.com and mark your subject line "URGENT". Our team monitors this address continuously.


Last updated: June 2025 | Crestox Platform

← Back to Home