Greetings to all members of the community! We noticed that there are a lot of security questions and prepared information for you on these issues!
First of all, Saifu is the first financial service that brings world-class security to the cryptocurrency world.
We use not just a HSM module, but
a combination of hardware and software technologies to deliver multi-layered security that does more to protect your Saifu account.
Our multi-layered security measures include:
- Data Encryption to help protect sensitive information
- Web Application Firewall
- Hypervisor and Internal Firewalls
- Anti-Malware
- Anti-DDoS (Distributed Denial of Service)
- Intrusion Detection & Prevention Syst
- Security Patch Management
- Operating System File Integrity Monitoring
- OS Hardening
- Secure Awareness Training Programs for Saifu employees
- Unified Security Management using an advanced Security Information & Event Management (SIEM) system
- Secure Architecture, including Source Code Audits and Penetration Tests
- Access Rights Management
- Incident Response Plan
To store private keys we use a hardware device from Thales security, a similar solution is used in many banks. The keys are created inside the device, but they can not be architecturally copied. There is access to the key, access through several levels of smart card. Even with their use, you can not extract the key. In the application, authorization via fingerprint/selfie, protection by behavioral pattern. Authorization via the web: on the phone/mail displays a message - is it you are sending a payment? Special multi-colored qr-code. The transaction is signed with a digital signature of the person. Safety from VASCO (
https://www.vasco.com/products/application-security/digipass-for-apps.html).
Logical structure of storage of funds: from the client side - a single cabinet. From our side, storage as a bank - on different accounts.
If you want to receive replies in real time, please contact our support agents in the
official Saifu Telegram channel. Also there is a
official Saifu Russian Telegram channel.