Time-based One-Time Passwords
Every login requires a fresh six-digit code from a device only you control. Codes rotate every 30 seconds using the RFC 6238 standard used by Google Authenticator and 1Password.
A private bank that loses your money is a private bank you will never see again. Everything below is enforced by default on every account, at every tier.
Every login requires a fresh six-digit code from a device only you control. Codes rotate every 30 seconds using the RFC 6238 standard used by Google Authenticator and 1Password.
Your authenticator secret is provisioned in person at enrollment and never leaves the device it was issued to. A stolen password alone cannot open your account.
Cryptographic keys for Bitcoin, Ethereum and tokenised assets are held in air-gapped hardware inside Swiss underground vaults. Signing requires quorum approval from separately-located officers.
Our platforms run on redundant Swiss and Frankfurt datacentres with continuous intrusion detection, automated failover and monthly third-party penetration testing.
TLS 1.3 on the wire. AES-256 at rest. HSM-backed key management. No client data ever leaves EU/CH jurisdictions.
Outgoing transfers above your personal threshold are held in a compliance queue and cleared by a named officer before funds move. Anomalies trigger a phone call before they trigger a wire.
Call your advisor immediately. If you cannot reach them, our 24/7 security desk answers within one ring.
REACH THE SECURITY DESK