iCryptoNow
Security

20 layers of protection

Every deposit and payout passes through 20 independent layers of defense, from the API request down to the chain. If one layer is ever bypassed, the next one still stands.

Layers 01–04

API protection

  1. 01Signed requests
  2. 02Replay protection
  3. 03IP allowlisting
  4. 04Signed webhooks
Layers 05–08

Key protection

  1. 05Hardware-secured keys
  2. 06Isolated signing
  3. 07Transaction policy engine
  4. 08Encrypted credentials
Layers 09–12

Payout controls

  1. 09Transaction limits
  2. 10Large-payout approval
  3. 11Duplicate protection
  4. 12Automatic payout freeze
Layers 13–16

Fund integrity

  1. 13Vault-locked addresses
  2. 14Independent verification
  3. 15Finality checks
  4. 16Immutable ledger
Layers 17–20

Operations

  1. 17Continuous reconciliation
  2. 18Network isolation
  3. 19Audited access
  4. 2024/7 monitoring & alerts

We don't publish how each layer works. Keeping those details private is part of what keeps them strong.

A vault of coins inside a protective shield
Our guarantee

If our system fails, we carry the loss. Not you.

If funds are lost because of a fault in iCryptoNow's own platform, we cover it in full. Your players are credited and your balance is made whole, at our cost.

We cover

  • Faults in our address generation, signing, sweeping and payouts
  • Breaches or failures of our servers and infrastructure
  • Errors in our ledger or balances

Outside our scope

  • API calls made with your keys if they leak from your systems
  • Deposit addresses changed or replaced on your platform
  • Anything else that happens on your side of the integration

Your part of the setup

Our guarantee covers our systems. These steps keep your side just as safe.

Keep secrets server-side

Store your API and webhook secrets in a secrets manager. Never ship them to browsers or apps.

Register only your servers

Allowlist only the outgoing IPs of the servers that call our API.

Verify every webhook

Check the signature and timestamp before crediting a player, and deduplicate on event_id.

How request signing works

Apply now