Crestox operates at the intersection of art, technology, and finance. That means the trust you place in this platform is not abstract — it is financial, legal, and personal. This page explains how we protect you, your investments, and the integrity of the marketplace.
Security Philosophy
Crestox is built on three foundational security principles:
Security by Design Security is not a feature added after the fact. It is embedded into every layer of the platform — from how accounts are created, to how artwork is verified, to how transactions are settled. Every system, workflow, and policy is designed with security as a baseline requirement.
Transparency We believe you have the right to understand how your data is handled, how your assets are protected, and what happens if something goes wrong. This page is part of that commitment.
Compliance Crestox operates within applicable legal and regulatory frameworks. Our security practices are designed not only to protect users but to meet and, where possible, exceed the obligations imposed on regulated financial platforms.
Account Security
Your account is the gateway to your investments. We apply multiple layers of protection to ensure only you can access it.
Password Protection
- All passwords are hashed using industry-standard cryptographic algorithms before storage. Crestox never stores your password in plain text.
- Passwords must meet minimum complexity requirements at the time of creation or reset.
- Crestox staff will never ask for your password under any circumstances. If you receive a request for your password from someone claiming to represent Crestox, do not comply and report it immediately to security@crestox.com.
Multi-Factor Authentication (MFA)
Multi-factor authentication is available to all users and strongly recommended. When enabled, logging in requires both your password and a one-time verification code sent to your registered device or authentication application.
To enable MFA, navigate to My Account → Security → Two-Factor Authentication.
Crestox may require MFA for certain high-value transactions or account changes, regardless of your account settings.
Session Management
- All authenticated sessions are time-limited. Sessions that remain inactive will expire automatically.
- You may view and terminate active sessions at any time under My Account → Security → Active Sessions.
- If you notice a session you do not recognise, terminate it immediately and change your password. Then contact security@crestox.com.
Device Monitoring
Crestox monitors login activity for signs of unauthorised access, including logins from unrecognised devices or unusual geographic locations. If a login attempt is flagged as suspicious, we will send a security alert to your registered email address.
If you receive a security alert for activity you did not initiate, follow the instructions in the alert immediately and contact our security team.
Data Security
Encryption
All data transmitted between your device and the Crestox platform is encrypted using TLS 1.2 or higher. This applies to all platform interactions, including account access, payments, and document uploads.
Sensitive data stored on our systems — including financial records and identity documents — is encrypted at rest using AES-256 encryption.
Secure Storage
User data is stored on secured infrastructure with access controls that restrict access to authorised personnel only. Our storage systems are subject to regular security review.
Identity documents submitted for KYC verification are stored separately from general platform data and are subject to enhanced access controls.
Access Controls
Internal access to user data is governed by the principle of least privilege: Crestox staff are only granted access to the data they require to perform their specific function. All internal access is logged and subject to audit.
No Crestox employee has standing access to financial credentials, payment card data, or authentication secrets.
Data Retention
We retain your personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law.
Upon account closure, personal data is handled in accordance with our Privacy Policy. Certain transaction and compliance records may be retained for the periods required under financial regulation, even after account closure.
For a full description of how your data is collected, stored, and used, please refer to our Privacy Policy.
Financial Security
Payment Gateway Partners
Crestox does not store payment card data on its own systems. All card transactions are processed through regulated, PCI-DSS compliant payment gateway partners. Your card details are transmitted directly to the payment processor and are never passed through or stored by Crestox.
Bank transfer details provided for wallet withdrawals are encrypted and stored securely, and are used solely for the purpose of processing your withdrawal.
Transaction Auditing
Every transaction on the Crestox platform — including fractal purchases, secondary market sales, wallet deposits, and withdrawals — generates an immutable audit record. These records are retained in accordance with applicable financial regulation and are available to authorised regulators upon request.
You may review your own transaction history at any time under My Account → Transaction History.
Fraud Detection
Crestox operates automated fraud detection systems that monitor transaction activity for patterns associated with fraudulent behaviour. Flagged transactions may be held for review before being processed.
If a transaction is held for review, you will be notified by email. Crestox may request additional verification before releasing a held transaction.
If you believe you have been the victim of fraud involving your Crestox account, contact security@crestox.com immediately. Do not attempt further transactions until the matter is resolved.
Artwork Security
The integrity of what is listed on Crestox is foundational to the value of every fractal on the platform. We apply rigorous controls to ensure that only verified, legitimate artworks are listed.
Artwork Verification
Every artwork submitted to Crestox is reviewed by our internal team before it is approved for listing. This review includes:
- Verification of the artwork's authenticity and provenance documentation
- Confirmation that the submitting party has the right to list the artwork
- Assessment of metadata accuracy (title, medium, dimensions, year of creation)
- Assignment of an internal grade reflecting the artwork's assessed quality and investment profile
Artworks that cannot be verified to the required standard are rejected. This is not a formality — it is how Crestox maintains marketplace credibility.
Ownership Verification
Before an artwork can be fractionalized and listed, the submitting party — whether an artist, curator, or owner — must complete identity verification and, where applicable, provide documentation establishing their right to list the artwork.
Curators are additionally required to provide written authorisation from the relevant artist before any listings may be managed on that artist's behalf.
Approval Workflow
No artwork, artist profile, achievement record, or historical sale is made publicly visible on the platform without passing through the Crestox approval process. This applies without exception. The curated nature of the platform is not a marketing claim — it is a structural safeguard.
Marketplace Integrity
The Crestox secondary marketplace is designed to be transparent and fair. We actively monitor marketplace activity to detect and prevent manipulation.
Anti-Manipulation Controls
The platform applies controls to prevent common forms of marketplace manipulation, including wash trading (a user buying and selling their own fractals to create artificial price movement) and coordinated listing behaviour designed to inflate or deflate perceived value.
Accounts found to be engaging in manipulative behaviour will be suspended and may be reported to relevant regulatory authorities.
Suspicious Trading Detection
Automated systems monitor trading activity across the marketplace for patterns that suggest coordinated manipulation, insider activity, or other forms of market abuse. Flagged activity is reviewed by the Crestox compliance team.
Where suspicious activity is confirmed, Crestox will take appropriate action, which may include transaction reversal, account suspension, and regulatory notification.
Listing Review Systems
All primary artwork listings undergo the approval process described in Artwork Security above. Secondary listings (fractal resales by collectors) are subject to automated screening and may be reviewed manually where activity is flagged as unusual.
Vulnerability Reporting
Responsible Disclosure Policy
Crestox welcomes good-faith security research. If you discover a vulnerability in our platform, we ask that you report it to us privately and responsibly before disclosing it publicly, so that we have the opportunity to investigate and remediate the issue before it can be exploited.
What to report:
- Authentication or authorisation bypass vulnerabilities
- Data exposure or leakage
- Injection vulnerabilities (SQL, XSS, etc.)
- Insecure direct object references
- Cryptographic weaknesses
- Any other vulnerability that could compromise user data or platform integrity
How to report:
Send your report to security@crestox.com with the subject line "Responsible Disclosure — [Brief Description]".
Your report should include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- The potential impact, as you assess it
- Any supporting materials (screenshots, proof-of-concept code)
What you can expect from us:
| Stage | Commitment |
|---|---|
| Acknowledgement | Within 3 business days of receipt |
| Initial Assessment | Within 7 business days of acknowledgement |
| Resolution Update | Within 30 business days, or sooner where possible |
We will not pursue legal action against researchers who report vulnerabilities in good faith in accordance with this policy, provided they do not access, modify, or delete user data beyond what is necessary to demonstrate the vulnerability, and do not disclose the vulnerability publicly before we have had a reasonable opportunity to address it.
Crestox does not currently operate a paid bug bounty programme. This may change in the future and will be communicated on this page.
Incident Response
In the event of a security incident, Crestox follows a structured response process designed to contain the impact, notify affected parties, and restore normal operations as quickly as possible.
Detection
Crestox operates continuous monitoring of its systems and infrastructure. Security alerts are reviewed by our team around the clock. Anomalies that may indicate a breach or attack are escalated immediately for investigation.
Containment
Upon confirming a security incident, our first priority is containment — isolating affected systems to prevent further exposure while preserving evidence needed for investigation.
Notification
Affected users: Where a security incident results in the unauthorised access to, or disclosure of, personal data, Crestox will notify affected users as soon as reasonably practicable after the incident is confirmed. Notification will be sent to your registered email address and will include a description of what occurred, what data was affected, and what steps you should take.
Regulatory notification: Crestox will notify relevant regulatory authorities in accordance with applicable data protection and financial regulation. Where required by law, notification will be made within the prescribed timeframe (typically 72 hours of confirming a personal data breach under applicable data protection law).
What we will never do: Crestox will not delay notifying users in order to minimise reputational impact, and will not issue notification that downplays the severity of a confirmed incident.
Recovery
Following containment, Crestox will conduct a full post-incident review to identify the root cause, remediate the vulnerability, and implement controls to prevent recurrence. A summary of findings and remediation steps will be published where appropriate and proportionate to do so.
Compliance & Certifications
Current Registrations
Crestox operates as a duly incorporated entity and maintains all registrations required to conduct its business activities under applicable law, including:
- Corporate registration under the laws of its jurisdiction of incorporation
- Applicable government and regulatory registrations required for operation as a financial technology platform
Specific registration details are available upon request to compliance@crestox.com.
Future Certifications & Audits
Crestox is actively working toward the following:
| Milestone | Status |
|---|---|
| ISO/IEC 27001 (Information Security Management) | In progress |
| Independent security audit by accredited third party | Planned |
| PCI-DSS assessment (platform-level) | Planned |
| Formal AML/KYC compliance programme review | Planned |
This page will be updated as certifications and audit results are obtained. We will not claim certifications we have not received.
Privacy Commitments
Crestox collects and processes personal data solely for the purposes necessary to operate the platform, comply with applicable law, and protect the security of users and the marketplace.
We do not sell your personal data to third parties. We do not use your data for purposes unrelated to your use of the platform without your explicit consent.
Your rights in relation to your personal data — including rights of access, correction, deletion, and portability where applicable — are set out in our Privacy Policy.
For privacy-related enquiries, contact privacy@crestox.com.
Security Contact
For all security-related communications:
| Purpose | Contact |
|---|---|
| Vulnerability reporting | security@crestox.com |
| Suspected account compromise | security@crestox.com |
| Privacy enquiries | privacy@crestox.com |
| Compliance & regulatory enquiries | compliance@crestox.com |
In the event of an urgent security concern — including a suspected account breach or active fraud — please contact us at security@crestox.com and mark your subject line "URGENT". Our team monitors this address continuously.
Last updated: June 2025 | Crestox Platform