Your funds are securely held by our FCA-regulated e-money partners at reputable credit institutions. In the unlikely event of insolvency, these funds create a protective pool prioritized for e-money holder claims, ensuring client funds are safeguarded above other creditors. These institutions, along with Currencycloud, have no direct access to your funds outside the scope defined in our Terms and Conditions.
Security
Ensuring the Security of Your Finances
Regulatory Framework and Compliance
Our operations adhere to stringent regulatory standards. Safeguarding payments is a critical consumer protection aspect mandated by the Electronic Money Regulations and the Payment Services Regulations. Currencycloud is a certified Electronic Money Institution (EMI), regulated by the Financial Conduct Authority (FCA) under the firm’s reference number 900199, in accordance with the Electronic Money Regulations 2011 and Payment Services Regulations 2017.
Commitment to the Protection of Client Funds
At CurX, the security of your finances is our top priority. We partner with The Currency Cloud Limited to provide impeccable payment services. This collaboration ensures the safekeeping, collection, and storage of client funds. Additionally, it facilitates foreign exchange conversions and processes outbound payments efficiently. Our arrangement guarantees that any e-money held for our clients is safeguarded. This means that in the event of Currencycloud facing administration or liquidation, your funds are protected and can be returned. This level of security surpasses what’s typically available through standard bank accounts, offering protection for all client funds, irrespective of their value.
Advanced Security Measures
Physical and Network Security
We utilize a state-of-the-art platform through Currencycloud, which meets the highest standards of security compliance, including:
- ISO 27001 Information Security Management
- PCI-DSS Level 1 Payment Card Standards
- ISO 27018 Personal Data Protection
- SSAE16/SOC 1, SOC2, and SOC 3
- FIPS United States Government Security Standards
Our network security infrastructure is designed to thwart a range of cyber threats, from DDoS to man-in-the-middle attacks. Currencycloud employs robust mechanisms against domain hijacking and phishing, supported by continuous penetration testing and defenses against common vulnerabilities.
Access Control
Our platform enforces stringent access controls, including role-based security models, two-step and multi-factor authentication for sensitive systems. All access attempts are meticulously logged and audited to detect and respond to any suspicious activity promptly.
Encryption and Information Security
We ensure that all network traffic is encrypted during transit, and sensitive information is encrypted while at rest, adhering to best practices for encryption key security. Our platform’s operational security is ISO/IEC 27001:2013 certified, demonstrating our commitment to the highest international standards for Information Security Management Controls. We are also compliant with the UK Data Protection Act (DPA) and the European Union General Data Protection Regulation (GDPR).