RISK, SECURITY & COMPLIANCE

Crypto Risk and Compliance Infrastructure, Pre-Integrated With Your Exchange

Five capabilities, five genuinely different jobs — AML, trade surveillance, listing due diligence, protocol review, and the security all four run on. Coiny supplies the software and evidence; licensing and conduct decisions stay with your team.

5capabilities
95%+in cold storage
24/7screening
Audit-readyevery decision
THE STACK

Five Capabilities, Five Different Jobs

Each card routes to the canonical page for that capability — its detection logic, its console, its operator controls and its own answers. Pick by the problem you are trying to solve, not by the word compliance.

PLATFORM AND CUSTODY

Exchange Security Infrastructure

The layer everything else runs on: asset custody, trading integrity, account access, withdrawal fraud and incident response. 95%+ of funds sit in cold storage, with HSM and multi-signature key protection.

  • Cold storage tiers with HSM and multi-signature signing
  • Hardened infrastructure, DDoS mitigation, intrusion detection
  • Two-factor, anti-phishing, device and role-based access control
Learn more
Isometric shield bearing a fingerprint, surrounded by a padlock, password field, crypto coins and server stacks
CUSTOMERS AND FUNDS

AML, KYC and KYT Compliance

Answers who your customers are and where their funds come from: tiered identity verification, sanctions and PEP screening, FATF Travel Rule handling, transaction monitoring and filing-ready SAR workflows.

  • Tiered identity verification, native or via Sumsub and iDenfy
  • OFAC, sanctions and PEP screening with match confidence
  • Transaction monitoring and filing-ready SAR case workflow
Learn more
Compliance panels for identity verification, biometric liveness check, sanctions and PEP screening, and KYC tier status
MARKET CONDUCT

Trade Surveillance & Market Integrity

Answers how participants behave, a different question from who they are. Spoofing, layering, wash trading and cross-market manipulation, clustered to the accounts behind them, with order-book replay.

  • Spoofing, layering, wash trading and abnormal execution
  • Account clustering across devices, funding paths and timing
  • Market replay, case management and market-integrity reporting
Learn more
An alert queue flagging spoofing, reviewing layering and clearing a wash trade, beside order book replay and linked accounts
ASSET ADMISSION

Token Due Diligence & Asset Risk

Answers whether an asset belongs on your venue: contract behaviour, holder concentration, unlock schedules, real liquidity and governance, composed into a listing-risk report with a decision record.

  • Privileged functions, upgrade paths and transfer restrictions
  • Holder concentration, insider supply and unlock schedule
  • Listing-risk report, committee decision record and re-review triggers
Learn more
A token review scoring 72 on a gauge, beside checks passing on liquidity and warning on holders
PROTOCOL DEPENDENCIES

Smart-Contract Security & DeFi Risk Reviews

Answers whether a protocol is sound enough to depend on. These are reviews and risk assessments, not independent audits — Coiny does not certify that a contract is safe.

  • Contract logic and access control with the holder of every role
  • Oracle staleness and deviation caps, bridge and relayer risk
  • Findings with severity, remediation guidance and post-fix re-test
Learn more
A contract scan finding no reentrancy and one access control issue, beside 98 percent coverage
DEFENSE LAYERS

How the Five Layers Wrap Around One Set of Operations

These are not five products sitting beside each other. They are five layers around the same matching engine, the same wallets and the same user base — each reading different data and answering a different question.

Diagram: custody, platform, surveillance and compliance defense layers around exchange operations, from platform and custody security through customer and funds compliance, market conduct, asset admission and protocol dependency review

At the centre sit the operations a venue runs: the matching engine, the wallets behind it, and the users and listings on top. Security is the innermost layer, AML and KYT establish who each customer is, surveillance reads the order lifecycle, and the outer two gate what gets listed and what gets integrated.

CHOOSE A CAPABILITY

Which Capability Answers Which Problem

Buyers confuse these constantly, and the confusion is expensive: an AML vendor will not catch spoofing, and a surveillance engine will not tell you whether a token should be listed. The conclusion of the table below is that these are five different jobs, with five different data sources and five different owners. Buying one does not cover another — but running all five on one platform means they share evidence instead of contradicting each other.

#CapabilityThe question it answersWhat it readsWhat it produces
1Platform and custody securityOwned by the CISO and security engineeringCan the platform or the keys be broken into?The precondition for everything elseInfrastructure, keys, sessions, withdrawalsCold storage tiers and signing policyA hardened platform and controlled fund movementPlus incident response when prevention fails
2Customer and funds complianceOwned by the MLRO and the compliance functionWho is this customer, and where did the funds come from?Identity and provenance, not behaviourIdentity documents, sanctions and PEP lists, fund flowsDeposits, withdrawals and counterpartiesVerified customers, screened flows, filed reportsFiling-ready SAR cases with an audit trail
3Market-conduct surveillanceOwned by market conduct or compliance surveillanceHow are participants behaving in our markets?Behaviour, not identityOrders, amendments, cancellations, fills, account linksStraight from the matching engineManipulation alerts, replay and a defensible case fileSpoofing, wash trading, cross-market patterns
4Asset admission due diligenceOwned by the listing committeeShould this token be listed on our venue at all?A gate, decided once and re-opened on triggersContract, holders, liquidity, governance, treasuryPlus the token's own transaction historyA sectioned listing-risk report and a decision recordSeverity on every finding, thresholds set by you
5Protocol dependency reviewOwned by whoever signs off integrationsIs this protocol sound enough to depend on?A gate on what you connect toContract logic, privileged roles, oracles, bridgesAnd the economics under stressFindings with severity, remediation and a re-testA review, never an audit certificate
COVERAGE

What the Stack Actually Covers, Control by Control

The five capabilities above break down into the controls a security review or a licence application will ask you about, in the language those documents use.

icon

Asset custody and key protection

95%+ of funds in cold storage, with hot, warm and cold tiers each carrying their own signing policy. Keys are protected with HSM, multi-signature and MPC, and Proof of Reserves lets holdings be verified rather than asserted.

icon

Hardened platform infrastructure

Multi-layer firewalls, DDoS mitigation, intrusion detection, secure coding practice, penetration testing and continuous vulnerability scanning. Modular microservices run isolated, so an attack surface stays contained.

icon

Account access protection

Two-factor authentication, biometric login, anti-phishing codes, login monitoring, IP allowlisting and device management. Administrators get role-based access, so permissions are scoped to the job.

icon

Withdrawal fraud controls

Every withdrawal passes layered automated checks before release: threat detection for laundering and coordinated attacks, account reputation and pattern analysis, and intelligence on compromised assets.

icon

Identity verification and tiering

Automated document, liveness and address verification with tiers configured per jurisdiction and product. Runs on the native KYC module, or through integrated providers such as Sumsub and iDenfy.

icon

Sanctions, PEP and Travel Rule screening

Automated screening against the major sanctions databases including OFAC, with match confidence scoring, PEP detection and Travel Rule handling. Screening runs at onboarding and continuously afterwards.

icon

Transaction monitoring and KYT

Continuous surveillance across every fund movement, scoring counterparty exposure, mixer proximity, structuring and velocity against your thresholds. Alerts land in one console with the trigger reason attached.

icon

Market manipulation detection

Detection for the conduct that invites regulatory attention: wash trading, spoofing and layering, ramping, abnormal execution, and bots exploiting market makers through latency. Cross-market patterns raise one alert.

icon

Listing and integration gates

Risky-asset controls before anything reaches your order book. Both due diligence and contract review re-open on triggers such as an upgrade, an owner change or liquidity falling below your threshold.

OPERATOR QUESTIONS

What Compliance Officers and CISOs Ask Before They Sign Off

Risk and compliance is the part of a platform evaluation where vague answers cost the deal. These are the questions that decide it.

  • Do we still need a separate AML vendor and a separate surveillance vendor?That depends on your obligations and your advisers, not on us. What Coiny Exchange removes is the integration and reconciliation work between them: AML monitoring, trade surveillance, listing due diligence and platform security all read the same exchange data and write to the same evidence trail, so an investigation does not start by exporting from three systems that disagree.
  • Where does Coiny Exchange's responsibility end?At the evidence. Coiny supplies the detection engines, the reports, the case workflow and the audit trail. It does not certify that a venue is compliant, does not issue audit certificates, does not provide legal advice and does not obtain licences. Every conduct determination, listing decision and integration approval is made by your team, on the record the platform produces.
  • Can our own thresholds and policies drive it?Yes, and they should. Verification tiers, screening lists, monitoring thresholds, surveillance sensitivity, holder-concentration limits, liquidity floors and the findings that force a committee vote are all operator-configured. Coiny supplies the analysis and the workflow; the risk appetite is yours to set and to change without a release.
  • What happens to the evidence when a regulator or auditor asks?It is already assembled. Every alert keeps the data that triggered it, every investigation keeps its case file and replay, every listing decision keeps its report and the committee record, and every remediation keeps its re-test result. Records are exportable, so a request is answered from the platform rather than reconstructed from screenshots and email.
  • Can this run on an exchange we did not buy from Coiny?The stack is at its strongest on the Coiny platform, where surveillance takes the matching engine directly as its data source and there is no market-data integration project. Token due diligence and smart-contract security reviews are engagement-based and are not tied to the platform at all. Bring the venue you run and we will be specific about what applies.
Talk to a Compliance Specialist
GO DEEPER

Every Capability in the Risk Stack

Each link below is the canonical page for that capability — what it detects, the console your team works in, what an operator configures, and its own answers.

Autonomous AI security testing

Specialist AI agents assess code, cloud, contracts and payment flows continuously, and publish a finding only when reproducible evidence supports it.

exchange security infrastructure

The layer everything else runs on: cold storage tiers, HSM and multi-signature key protection, hardened infrastructure, account protection, withdrawal fraud controls and incident response.

AML/KYC/KYT compliance

Who your customers are and where their funds come from: tiered identity verification, sanctions and PEP screening, transaction monitoring and filing-ready SAR workflows.

trade surveillance & market integrity

How participants behave in your markets: spoofing, wash trading and cross-market manipulation detected from the matching engine, with account clustering, market replay and case files.

token due diligence & asset risk

Whether an asset belongs on your venue: contract findings, holder concentration, liquidity, governance, treasury and transaction risk in one sectioned listing-decision report.

smart-contract security & DeFi risk reviews

Whether a protocol is sound enough to integrate: contract logic, access control, oracle and bridge dependencies and protocol economics, with remediation and post-fix verification.

COMMON QUESTIONS

FAQ

A crypto exchange needs five distinct systems: platform and custody security, AML/KYC/KYT for customer identity and fund provenance, trade surveillance for market conduct, due diligence on every asset before it is listed, and security reviews of any protocol it integrates. Coiny Exchange ships all five pre-integrated with the trading platform, so each reads live exchange data rather than a copied feed. Licensing and legal interpretation remain with the operator.

No. Coiny Exchange supplies compliance infrastructure — the systems, the evidence and the workflow a compliance programme runs on — not a compliance outcome. It is not a law firm, a regulator, an auditor or a licensing agent, and it does not certify that a venue is compliant. The software is designed to support obligations such as MiCA market-abuse provisions and FATF Travel Rule requirements; the licence application, the legal interpretation and every determination stay with your compliance team and advisers.

Yes. Each of the five capabilities in Coiny Exchange's risk, security and compliance stack deploys on its own — trade surveillance without token due diligence, AML and KYC without smart-contract reviews. Because they run on the same platform and read the same exchange data, adding a second capability later is a configuration step rather than a second integration, and the evidence from all of them lands in one place instead of three disconnected consoles.

Pre-integrated means the compliance systems read the exchange's own data directly instead of a copied feed. Coiny Exchange's trade surveillance takes the matching engine as its data source, AML monitoring sees deposits and withdrawals as the ledger records them, and listing decisions attach to the assets the venue actually trades. For a compliance team that removes the market-data integration project, the reconciliation between systems, and the lag that lets an alert fire on stale state.

Different teams own different layers, which is why buyers confuse them. Platform and custody security belongs to the CISO and security engineering. AML, KYC and KYT belong to the money laundering reporting officer and the compliance function. Trade surveillance belongs to market conduct. Token due diligence belongs to the listing committee. Protocol security reviews belong to whoever signs off integrations. Coiny Exchange gives each of them its own console over one shared platform.

Coiny Exchange does not issue audit certificates, act as an independent auditor, or certify that a contract, a platform or a venue is secure or compliant. It does not provide legal advice, obtain regulatory licences, or make listing, conduct or integration decisions on an operator's behalf. It supplies the detection engines, the reports, the evidence and the workflow; the risk appetite and every decision remain the operator's.

DEPLOY THE RISK STACK

Bring the Problem You Actually Have

A regulator's question you cannot answer, a listing you are not sure about, a protocol you are about to integrate, or an alert queue nobody trusts. We will show you which layer handles it and what the evidence looks like when it does.

Talk to a Compliance Specialist