Security engineered into every layer.
Protecting client funds, data and access is not a feature we add later — it is part of how Solaris Black is designed, operated and monitored.
Defence in depth.
Security at Solaris Black is built on the idea that no single control is enough. We combine strong identity verification, encrypted communications, hardened infrastructure, strict access controls and continuous monitoring so that a weakness in one layer does not become a breach of the whole system.
Every design decision — from how you log in to how funds move — is reviewed against the same standard: would we be comfortable using this ourselves with serious capital at stake? That question shapes the controls you see, and many more that run behind the scenes.
We also believe security should be explainable. The sections below describe what we do, how we do it and what you can do to keep your own account safe.
Account protection
Multi-factor authentication, device controls, withdrawal allow-listing and step-up verification keep account access in the right hands.
- Active sessions and registered devices can be reviewed and revoked instantly from the account dashboard.
- Withdrawal addresses are allow-listed and any new address requires email confirmation and additional verification.
- Sensitive actions — password changes, email updates, large withdrawals and API key creation — trigger step-up verification.
- Automated lockouts and real-time alerts respond to repeated failed logins, unknown devices or unusual location patterns.
Data & key security
Client data and cryptographic material are encrypted, segmented and accessible only through least-privilege, audited systems.
- All traffic between clients and Solaris Black is encrypted with TLS 1.3, and internal service communication runs over mutually authenticated channels.
- Sensitive records are encrypted at rest using modern algorithms and key material protected by hardware security modules (HSMs) or equivalent key-management services.
- Access to production data is granted on a least-privilege basis, individually authenticated and continuously logged.
- API keys are scoped, can be restricted by IP and permission set, and can be rotated or revoked immediately from the account panel.
- Personal information is collected only when necessary, stored in segmented databases and never sold or shared for marketing purposes.
Resilient infrastructure
Geographically separated environments, isolated critical layers and tested failover keep the platform stable through volatility and incidents.
- Production workloads run across redundant, geographically separated data centers with automated failover and load balancing.
- Matching, risk, settlement and client-facing services are isolated into separate layers so a problem in one area cannot cascade into another.
- DDoS protection and rate limiting absorb large traffic spikes and protect order-entry endpoints from abuse.
- A disaster-recovery programme is tested regularly, with defined recovery-time objectives for trading, deposits and withdrawals.
- The majority of digital-asset holdings are kept in cold-storage systems that are not reachable from the public internet.
24/7 monitoring
Continuous surveillance of platform health, market flow and account behaviour lets us detect and respond to anomalies around the clock.
- Platform health, market data feeds and order flow are monitored in real time from multiple vantage points.
- Behavioural models flag unusual login patterns, rapid setting changes, abnormal trading or unexpected withdrawal requests.
- A dedicated incident-response process defines escalation paths, communication protocols and recovery steps for security events.
- Security and operations teams are on call at all hours, with clear runbooks for common compromise scenarios.
- Clients are notified promptly when we detect suspicious activity on their accounts and are guided through secure recovery steps.
Segregation, custody and transparency.
Client funds are held separately from Solaris Black operating capital in segregated accounts with regulated banking and custody partners. This means client balances are not used for company expenses, lending or proprietary trading.
For digital assets, we use a combination of hot wallets for daily operational needs and cold-storage systems for the majority of holdings. Wallet architecture, key ceremonies and access procedures are reviewed regularly.
We are working toward independent proof-of-reserves and third-party audit programmes, and will publish results once they have been formally verified.
Verified before it is claimed.
We do not publish security certifications or regulatory claims until they have been formally verified and maintained. Where Solaris Black or its entities hold licences, registrations or audit reports, the details will be listed on this page and updated as statuses change.
Our internal compliance programme covers anti-money-laundering checks, sanctions screening, transaction monitoring and staff training. These controls are designed to meet the requirements of the jurisdictions in which we operate and to protect the platform from abuse.
If you need a specific attestation, certificate or regulatory detail for a commercial review, please contact our team and we will provide verified documents where permitted.
Steps we recommend.
Use a strong, unique password
A password manager is the easiest way to generate and store long, unique passwords for every service.
Enable two-factor authentication
2FA adds a second check at login and makes stolen passwords far less useful to an attacker.
Verify communications
Solaris Black will never ask for your password, full private key or 2FA code by email, phone or chat.
Report anything suspicious
If you notice unexpected activity, contact support immediately so we can secure the account.
Open your Solaris Black account.
Set up in minutes and explore the platform on your terms.
Solaris Black Group entities are regulated in their respective jurisdictions as follows: (1) Solaris Black Exchange Limited is authorised to operate a multilateral trading facility for virtual assets; (2) Solaris Black Clearing and Custody Limited is authorised to provide clearing, custody and central securities depository services; and (3) Solaris Black Trading Limited is authorised to carry out the following regulated activities: (i) dealing in investments as principal; (ii) dealing in investments as agent; (iii) arranging deals in investments; (iv) managing assets; (v) providing money services; and (vi) arranging custody.
Risk Warning: Virtual asset prices can be volatile. The value of your investment may go down or up and you may not get back the amount invested. You are solely responsible for your investment decisions and Solaris Black is not liable for any trading losses you may incur.

