BIT has published version 2.0 of its Trust White Paper, setting out the security, custody, governance and compliance controls it says underpin its digital-asset and U.S. equities-linked operations. The document places operational risk management at the center of the platform’s offering, describing a system in which security staff can block high-risk product or technology changes and sensitive actions require approval from more than one authorized employee.
The release arrives amid persistent scrutiny of trading platforms, custodians and other digital-asset service providers after a series of security breaches across the sector. BIT’s updated paper focuses less on product features than on the internal processes intended to protect customer assets, monitor suspicious account activity and limit the damage from operational failures.
The company says its framework covers the full trading cycle, from risk checks before an order is placed through real-time monitoring and post-trade procedures. For leveraged and collateral-backed products, that includes customer and product due diligence, risk-parameter setting, ongoing position monitoring, alerts, default handling and liquidation processes.
Security team can halt high-risk changes
One of the strongest controls described in the white paper is a “one-vote veto” held by BIT’s security team. Under the framework, the security function can stop product plans, system architecture proposals or go-live changes when they present major security risks or do not meet baseline security and compliance standards.
That structure gives security personnel formal authority in decisions that can otherwise be driven by commercial deadlines or technical deployment schedules. In digital-asset markets, changes to wallet systems, trading engines, account permissions or withdrawal processes can create immediate exposure if controls are incomplete. A veto mechanism would give the security team a route to prevent a release before it reaches customers.
BIT also describes a “four-eyes principle” for high-risk operational tasks, including asset transfers, permission changes and trade instructions. At least two authorized people must take part in those actions, according to the paper.
The approach is designed to reduce single-person control over workflows that could lead to asset losses or unauthorized trading. It also creates a record of shared review for actions involving customer funds, system access or operational permissions.
Cold-wallet custody and hardware key controls
On custody, BIT says the majority of assets are kept in cold wallets, meaning wallets that are not continuously connected to the internet. The company says private keys are held in a FIPS 140-3 Level 3 hardware security module, or HSM, and cannot be accessed or exported in plaintext.
An HSM is a specialized device used to generate, store and use cryptographic keys within a controlled hardware environment. The purpose is to reduce the risk that a private key can be copied from a server, employee device or internal system and used outside approved processes.
The paper does not frame cold storage as a stand-alone defense. It places key management alongside approval controls, monitoring systems and incident-response procedures. That reflects a practical reality of platform security: losses can result from compromised credentials, flawed administrator tools, weak internal permissions or errors in withdrawal processing, even where assets are largely held offline.
BIT says it runs 24-hour dynamic monitoring for abnormal logins, unfamiliar devices and unusual withdrawal behavior. Depending on the level of identified risk, the platform may issue an alert, delay processing or send the activity for manual review.
Withdrawal delays and review queues can frustrate customers during volatile markets, but they create time for a platform to identify whether a transaction follows a suspected account takeover. Such controls are especially relevant when a malicious actor has gained access to an account but has not yet completed an irreversible transfer.
U.S. equities service discloses Bhutan structure
The white paper also provides additional detail on BIT’s U.S. equities-linked business. It identifies Matrix Gelephu Pte Ltd as the operating entity and says it is regulated by Bhutan’s Gelephu Financial Services Office, or GFSO.
BIT says its arrangements for the service cover customer accounts, clearing and asset custody, with licensed third-party financial institutions participating where applicable. Those disclosures matter because equities-linked services involve a different operational chain from crypto spot or derivatives activity, potentially bringing together a platform operator, custodians, clearing providers and regulated financial entities.
The document also includes governance and regulatory information for Matrixport Asset Management, or MAM. BIT describes compliance positioning across Hong Kong, Bhutan, Singapore, Switzerland, the United Kingdom, the United States and the British Virgin Islands, reflecting the cross-border structure often used by firms that provide custody, trading, tokenized real-world asset and asset-management services.
Audits form part of the assurance framework
For external assurance, BIT cites ISO management-system audits, SOC independent attestations, annual financial audits and internal audits across relevant entities and business lines. SOC reports are third-party assessments of controls relevant to security, availability, confidentiality or financial reporting, depending on the type of engagement.
The company groups its trust framework around three areas: regulatory and compliance foundations, independent audits and attestations, and technical and operational transparency. The model places external reviews alongside internal control design rather than treating certification as a substitute for day-to-day defenses.
For customers assessing a platform, the practical test is whether controls described in a white paper are backed by clear operating procedures: segregated authorization for transfers, monitored withdrawals, restricted key access, defined incident handling and identifiable regulated entities for the services being offered. BIT’s updated document seeks to present those components as a connected system, covering digital-asset custody and trading controls alongside its expanding equities and asset-management operations.
For deeper insight into exchange security and risk controls, explore Toobit’s safeguards in this detailed guide.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
