Security architecture
Financial platforms are judged on what happens when something goes wrong. These are the controls built into DFX Globals.
Account security
- Secure authentication with hashed credentials
- Two-factor authentication architecture
- Session management and sign-out across devices
- Rate limiting on authentication and quoting endpoints
- Security alerts for sensitive account changes
Platform security
- Role-based access control for staff and business team members
- Server-side and client-side input validation
- Protection against cross-site scripting, request forgery and injection
- Provider credentials held as server-side secrets, never exposed to the browser
- Webhook signature verification and idempotent event processing
- Private document storage with time-limited signed access
Payment data
DFX Globals does not store raw card details. Card handling, where offered, is performed through PCI-compliant payment providers using tokenisation.
Auditability
Sensitive actions — approvals, rejections, compliance decisions, pricing changes, provider changes and environment changes — are written to an append-only audit log with the actor, timestamp, resource and before/after state.
DFX Globals is a financial technology platform. Certain payment and FX services may be provided through regulated third-party financial institutions and payment providers. DFX Globals is not a bank and does not claim any licence or regulatory registration unless verified details are published on the Legal Information page.