Security

Honest about what we do.

A summary of the technical and operational controls that protect your data on CCtoUSDT. We don't claim certifications we don't hold.

Technical controls

  • All traffic served over HTTPS with modern TLS; HSTS is enabled on the production domain.
  • Front-end and edge layer delivered via Cloudflare, with DDoS protection and Web Application Firewall rules at the perimeter.
  • Application backend and database run on a managed Postgres service with encryption at rest provided by the cloud vendor.
  • Sensitive credentials (API keys, signing secrets, third-party tokens) are stored as encrypted secrets and are not present in the client bundle.
  • User passwords are never stored in plain text; password authentication uses the managed auth provider's bcrypt-based hashing.
  • We do not store card numbers, CVV or full PAN data on our servers. Card collection is delegated to the upstream payment processor.
  • Database access is scoped via row-level security policies; administrative access is restricted and audited.
  • Deployments are immutable and versioned; rollback is possible at any time.

What we are honest about

We do not currently hold SOC 2, ISO 27001 or PCI-DSS Level 1 certifications. If these are required for a counterparty engagement, contact us and we will outline a realistic timeline.

We do not hold insurance from Lloyd's of London or any other underwriter against customer crypto losses. Because USDT is delivered directly to a wallet address you control, there is no on-platform crypto balance for us to insure.

We do not guarantee that any system is impenetrable. No platform should make that claim. We commit instead to clear disclosure, prompt incident response and a working channel for security researchers.

Account security guidance

  • Verify the destination wallet address before confirming a transaction โ€” blockchain transfers are irreversible.
  • Use a wallet you fully control. We will never ask you for your seed phrase or private key.
  • Beware of impersonation: our staff communicate only from @cctousdt.com email addresses and the in-product live chat.
  • If something looks wrong, contact support before sending funds. We would rather you ask than lose money.

Reporting a vulnerability

We welcome coordinated disclosure. Emailsecurity@cctousdt.comwith a clear reproduction. We aim to acknowledge reports within two business days. We do not currently run a paid bug-bounty program; we will credit researchers (with permission) for verified findings.

Ready to move money without borders?

Buy USDT in minutes or integrate the most reliable crypto payment rail in 24 hours.