What you can check for yourself, and what we do not publish. Both halves matter, and most pages like this one only print the first.

What you can check

Everything here exists and works today. None of it asks you to take our word for anything.

What we do not publish

Named rather than left out. If any of these is attributed to Crpko somewhere, it did not come from us.

  • Security certifications

    Crpko does not claim ISO 27001, SOC 2 or any equivalent on this site. Where a certification exists it will be named here with its scope and its date, because a badge without either tells you very little.

  • Proof of reserves

    No reserve attestation is published. This is the strongest thing an exchange can show and the hardest to fake, and until there is one this page will say there is not.

  • Independent audits and penetration tests

    No audit report or test summary is published. If one is commissioned, what it covered and when belongs here rather than in a sentence about being independently audited.

  • Insurance

    No insurance arrangement is claimed. Cover of this kind is specific about what it protects and what it excludes, and a general reassurance is not a substitute for those details.

  • Regulatory registration

    No registration is asserted on this site. Where one applies it will be stated with the registering body and the number, so it can be checked against that body rather than taken from us.

Questions

Because the alternative is a row of badges, and a badge you cannot check is worth very little. Naming the gaps lets you ask us for them, and it means nothing on this page quietly becomes untrue as the company grows. When one of them becomes real it will appear here with its scope and its date.

Not as far as this site claims. No ISO 27001, no SOC 2, no published audit and no reserve attestation. If you have seen any of those attributed to Crpko somewhere else, it did not come from us, and the contact verifier is the way to check whether the source was really ours.

To Sumsub, the third party that carries out verification. They perform the checks and return the result to us. The KYC page sets out what is submitted and what comes back.

Put the email address, handle, domain or number into the contact verifier. Anyone who reaches out first is worth checking, and we will never ask you for a password, a one time code or a recovery phrase.

Use a password that exists nowhere else, and turn on two factor authentication before you fund the account. Between them they stop the great majority of account takeovers, and neither depends on anything we do.

This page describes what Crpko publishes and what it does not. It is not a security guarantee, and it is not investment advice. See our risk disclosure.