Security

Production-grade infrastructure. Built for what matters.

The security of every asset on Fusang – and of every client who trusts us with them – is the foundation this business was built on. Here's how we deliver it.

Security at Fusang isn't a single feature or a certificate on a wall. It runs through how we're regulated, how we hold client assets, how we build and run our technology, and how our people operate. This page sets out each of those layers.

Regulated exchange, custody & trust licences
ISO/IEC 27001–aligned ISMS
Smart contracts audited by CertiK
MPC self-custodial wallets

How it fits together

Six layers, each one load-bearing

None of these stand alone – regulation without custody discipline is just paperwork, and custody without operational security is just a promise. Together, they're the whole answer.

Layer 1 – Regulation

Regulated and supervised

Fusang isn't a technology startup that stumbled into finance. From inception, we've operated as regulated financial market infrastructure, under ongoing supervision – not as a platform working around the rules.

That means continuous regulatory oversight, periodic regulatory reporting, independent annual audits, and fit-and-proper standards for every person in a licensed role. Every product we ship is built to satisfy our regulators, not to work around them.

View our licences

Our exchange, money-broking, fund-management and trust licences, and the regulators behind them, are listed in full on our licences page.

Frameworks and standards we hold ourselves to

Compliance isn't a box we tick. It's how we're built.

  • AML / CFT. Every client and every transaction is screened against international anti-money-laundering and counter-terrorist-financing standards, aligned to FATF guidance. Onboarding, ongoing monitoring, and sanctions screening are continuous, not one-off.
  • Information security – ISO/IEC 27001. Fusang operates under the same information security management system used across Portcullis Group, which includes entities certified to ISO/IEC 27001 (such as Portcullis Trust Services Limited). Policies, access governance, and risk management follow that framework group-wide.
  • Independent assurance. Our controls are subject to independent annual audit and to ongoing review by qualified third parties.

Layer 2 – Custody

Your assets, fully backed and independently held

Every Fusang Depository Receipt (FDR) is fully backed by the underlying institutional security, held by independent third-party custodians. A token balance on Fusang is not an IOU – it's a claim on a real asset, redeemable for the original instrument.

This matters because the history of digital assets is full of platforms that commingled client assets, rehypothecated them, or couldn't prove they existed. Fusang is structured on the opposite principle: segregation, independent custody, and on-chain transparency from day one.

Client funds are held separately from firm funds. Positions are reconciled against the underlying on an ongoing basis, and that reconciliation is subject to independent audit. Settlement is on-chain and auditable.

Layer 3 – On-chain

On-chain transparency and smart-contract security

Fusang is built on public blockchain infrastructure by choice – because it gives clients guarantees that closed systems cannot.

  • Verifiable on-chain. Every issuance, trade, and redemption is recorded on a public blockchain – not just in our internal database. Token supply can be verified by anyone, at any time, against the custodied underlying. You don't have to take our word for what we hold.
  • Independently audited. Our smart contracts have been independently audited by CertiK, a leading blockchain security firm, prior to deployment.
  • Standards-based architecture. Our contracts follow battle-tested, widely-reviewed open-source patterns rather than bespoke, unproven code.
  • Self-custodial wallet security. Client wallets use multi-party computation (MPC) key management through our wallet infrastructure provider – so a private key is never held or reconstructed in a single place.

Verify our core contracts on Ethereum: Swap router · FSC · BBL

Layer 4 – Platform

How the platform is secured

We run on the same foundations institutional banks rely on – not because it's trendy, but because we have to.

  • Encryption end-to-end. Data is protected with bank-grade encryption – AES-256 at rest, TLS 1.2+ in transit – wherever it sits and wherever it moves.
  • Zero-trust access. No one on the team gets privileged access without proving who they are, on an approved device, every single time. No shared passwords. No VPN perimeter.
  • Hardened infrastructure. Production systems run on Cloudflare and AWS – providers independently certified to ISO/IEC 27001, SOC 2 Type II and PCI DSS. The edge is protected by web application firewalling, DDoS mitigation, and bot management.
  • Monitored and backed up. Production systems are logged and monitored, and production data is backed up and encrypted. Credentials and keys are held in managed secrets stores, not in code.
  • Controlled change. Production systems are isolated. Changes are peer-reviewed and version-controlled. Nothing ships without passing automated security checks.
  • A real incident response plan. Severities are defined, response times are committed, regulators are notified when they need to be, and every significant incident is followed by a blameless post-mortem and tracked corrective actions.

Layer 5 – People

People and operational security

Most security failures start with people and process, not code. We treat that as a first-class risk.

  • Vetted people. Staff in sensitive and licensed roles are subject to fit-and-proper vetting before they're trusted with access.
  • Least privilege. Access is granted on a need-to-know basis, scoped to the role, and updated when someone joins, changes role, or leaves.
  • Segregation of duties. Sensitive actions require more than one person; no single individual can move client assets unchecked.
  • Security as a habit. Our team operates under clear information-security policies, with security awareness training built into onboarding and standard practice.

Layer 6 – Data

How we handle your data

Protecting client assets means protecting client data with the same discipline.

  • We collect only the data we need to operate, meet our regulatory obligations, and serve you.
  • Personal data is encrypted, access to it is restricted and logged, and it is retained only as long as our regulatory obligations require.
  • We do not sell client data.
Table of contents

Get in touch

Talk to our security team

If you'd like to understand our security and controls in more depth, we're happy to talk.

For institutional clients, due-diligence teams, and partners, a Security & Compliance Overview pack is available under NDA on request.

Reach our security team

Believe you've found a security issue in a Fusang product? Email the same address with the details. We acknowledge within 3 business days, and we won't take legal action against researchers who act in good faith.