Security architecture

Engineered so a single mistake cannot silently move funds.

Core control

Dual verification of derivation

HD derivation with independent second verification before credit or signing.

Gate A โ€” Derive

Primary derivation

Address generated along a fixed path from protected key material.

Gate B โ€” Re-derive & match

Independent verification

Mismatch aborts credit or signing.

Why this matters Address poisoning and copy errors are common loss vectors.

Withdrawals

Dual-control outbound authorization

Two independent authorization gates before release.

01

User confirmation

Approve withdrawal intent in the Auth bot.

02

Second factor release

Second factor armed only after confirmation.

03

Isolated signing

Hot signing as a constrained service.

Audit & standards posture

Aligned with widely recognized frameworks:

  • OWASP Top 10
  • ISO/IEC 27001 themes
  • PCI DSS themes (where analogous)

Live controls are the operational guarantee until attestations are published.

Operational hygiene

  • Token allowlists on operational wallets.
  • Canonical contract addresses only.
  • Public withdrawal pools for monitoring.

Security: contact@nvexc.com ยท Legal: legal@nvexc.com