Security

Security built into every layer, not bolted on

Encryption in transit, identity-first onboarding, least-privilege staff access, dual approval for privileged actions, and append-only audit trails.

This page is maintained and self-published by AntilFi. It describes our internal practices and is not an independent certification, audit report, or attestation. We do not claim compliance with any specific external certification or standard on this page.

Illustration of layered platform security: shield, key lattice, and identity contours
AST-005 · v1.0Conceptual artworkLayered controls: encryption, identity, least-privilege access, and audit history.

Encryption in transit

Traffic between your device, this portal, and the AntilFi platform is encrypted in transit using industry-standard transport security. We apply this consistently across the public site, onboarding flows, and every dashboard in the platform.

Identity-first onboarding

No account can transact before completing email verification, phone verification, and identity verification. Business accounts additionally verify company registration and the individuals who control the business, before merchant or agent tools are activated.

Role-scoped, least-privilege access

Internal staff access is scoped to the minimum needed for their role. A support agent, for example, cannot view or modify settlement configuration, and a merchant cashier role cannot see banking details. Access is reviewed on a regular cadence and revoked immediately when no longer needed.

Dual approval for privileged actions

High-impact actions — such as changes to settlement configuration, limit overrides, or platform configuration changes — require review and approval from a second authorized person before they take effect. No single individual can unilaterally make these changes.

Immutable audit trails

Sensitive actions across the platform — account changes, privileged access, settlement adjustments — are recorded in append-only audit logs. These records support internal review, dispute resolution, and investigation, and cannot be altered after the fact.

Reporting a vulnerability

If you believe you have found a security vulnerability affecting AntilFi, please report it responsibly rather than exploiting or publicly disclosing it before we've had a chance to respond. We aim to acknowledge reports promptly and will keep you informed as we investigate.

security@antilfi.com