BIT has published Trust Whitepaper V2.0, setting out a control framework that combines continuous risk monitoring, cold-wallet custody, hardware-based key protection, compliance structures and independent assurance across its digital-asset and traditional-finance services.
Released on Sept. 10, the document presents the company’s operational model as a three-part framework built around regulatory foundations, audit and assurance processes, and technical transparency. BIT said the framework covers activity before, during and after transactions, including lending, collateral management, account security and asset transfers.
The paper arrives as trading platforms face sustained pressure to demonstrate how they protect customer assets, manage operational failures and oversee products that increasingly sit alongside regulated securities services. BIT’s document places particular emphasis on internal controls that can delay transactions, escalate them for human review or halt activities judged to create material security or compliance risks.
Monitoring extends from account behavior to loan liquidation
BIT’s risk management and governance framework applies separate controls at different stages of a transaction. Before an activity takes place, the platform describes due diligence and transaction-specific parameters designed to assess potential risk. During execution, it uses real-time monitoring and alerts. Afterward, its framework includes procedures for handling defaults, disputes and other operational outcomes.
Margin lending and collateralized lending receive a more detailed treatment in the whitepaper. BIT said these services involve customer due diligence, lending parameters set for individual transactions, live risk monitoring, default-management procedures and liquidation processes.
Those provisions reflect the particular sensitivity of credit products in cryptocurrency markets. A lending platform must track changes in collateral values and borrower positions fast enough to enforce agreed terms, especially during sharp market moves. The whitepaper does not set out individual collateral thresholds or liquidation formulas, but it describes a system intended to monitor risk throughout the life of a loan rather than only at onboarding.
BIT also said it continuously reviews user behavior and transaction activity. Automated systems are designed to flag anomalous logins, unfamiliar devices and unusual withdrawal behavior. Depending on the assessed risk, those signals can trigger a delay or manual review.
For account holders, the arrangement means routine security signals may have operational consequences. A withdrawal from a new device or an unexpected location could face additional checks before execution, particularly if it coincides with other account changes or unusual transaction patterns.
Cold storage and hsm controls form the custody model
The whitepaper says the majority of assets are held in cold wallets, meaning wallets kept outside an internet-connected environment. BIT said the private keys protecting those wallets are stored in hardware security modules, or HSMs, certified to FIPS 140-3 Level 3.
FIPS 140-3 is a security standard administered by the U.S. National Institute of Standards and Technology for cryptographic modules. Level 3 includes requirements intended to make physical tampering more difficult and to enforce stronger controls over access to cryptographic keys.
BIT said private keys are never exposed in plaintext form. In practice, that is meant to prevent employees or systems from viewing and copying a usable key even where they are authorized to initiate approved processes involving it.
The firm’s internal approval design adds a “four-eyes” principle for high-risk activities. Under this approach, at least two authorized individuals must approve actions such as asset transfers, account-security changes, privilege modifications and transaction approvals.
Multi-person approval requirements can reduce the risk that one compromised account, malicious employee or operational error leads directly to an irreversible transfer. They can also introduce more processing steps, particularly for high-value or unusual transactions, making the company’s alert and review systems central to how quickly flagged activity is resolved.
BIT’s framework also includes a security veto authority. According to the document, this authority can suspend an activity if product designs, business requirements, architecture changes or production deployments create material security risks or fail to meet baseline security or compliance requirements.
That structure gives security personnel a formal route to stop commercial or technical changes before they reach customers. The practical value of such a mechanism depends on its use in day-to-day governance, but its inclusion places security review above purely operational approval for the activities described.
Securities operation sits under Bhutan licensing
For its securities business, BIT said BIT Securities is operated by Matrix Gelephu Pte Ltd., which holds a financial services licence issued by the Gelephu Financial Services Office in Bhutan. The company said the entity is subject to applicable requirements of the GFSO.
The whitepaper also states that its U.S. stock-trading services rely on applicable regulatory licensing, account and clearing arrangements, licensed third-party institutions and publicly verifiable regulatory information. It does not describe those arrangements as a single universal structure, reflecting the fact that securities services can involve several licensed entities with distinct responsibilities for brokerage, custody, clearing and execution.
BIT included regulatory and governance information for Matrixport Asset Management and listed group entities with regulatory or licensing presences in Hong Kong, Bhutan, Singapore, Switzerland, the United Kingdom, the United States and the British Virgin Islands.
Availability remains jurisdiction-dependent. BIT’s disclaimer says products and services may not be offered in every location and remain subject to regulatory requirements and customer eligibility restrictions.
Audit disclosures set out assurance layers
BIT’s audit and assurance framework lists ISO management-system audits, SOC third-party assurance reports, annual financial audits and internal audit mechanisms. The company said these measures apply differently depending on the entity and business line.
SOC reports are assessments of controls performed by independent service auditors, while ISO audits examine whether a management system meets a specified international standard. Neither format alone guarantees that a platform will avoid a security incident or financial loss, but both can provide structured evidence on how designated controls are designed and operated.
The whitepaper’s emphasis on external assurance, licensing and operational controls suggests BIT is seeking to make its risk framework legible across a business that includes digital assets, lending and securities-related services. Rather than relying on a single custody claim, the document links asset protection to monitoring systems, approval rules, internal authority structures and entity-level regulatory arrangements.
The full Trust Whitepaper V2.0 is available on BIT’s website.
For deeper insight into exchange safeguards, explore Toobit’s security standards in this guide on risk control.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
