Because the alternative is a row of badges, and a badge you cannot check is worth very little. Naming the gaps lets you ask us for them, and it means nothing on this page quietly becomes untrue as the company grows. When one of them becomes real it will appear here with its scope and its date.
What you can check for yourself, and what we do not publish. Both halves matter, and most pages like this one only print the first.
What you can check
Everything here exists and works today. None of it asks you to take our word for anything.
- Contact verifierCheck whether an email, handle, domain or phone number really belongs to Crpko.Impersonation is the attack that actually reaches people. This is the one tool here that helps before anything has gone wrong.Open
- How verification worksIdentity checks are carried out by Sumsub, a third party. Your documents go to them, not to us.Naming the processor is the part most pages leave out, and it is the part that tells you where your documents actually go.Open
- Anti money launderingWhat the programme covers, what it may ask of you, and the specifics not published yet.Including a list of what is missing from it, which is the part worth reading.Open
- Privacy PolicyWhat is collected, what it is used for, and who it reaches.The document that governs everything the other pages describe.Open
- Terms of ServiceThe agreement between you and Crpko.Worth reading before funding an account rather than after.Open
Securing your own account
The steps below are the ones in your hands, and they do more than anything on our side of the line.
- 1
Use a password that exists nowhere else
Almost every account taken over is taken with a password that leaked from somewhere unrelated. A password manager solves this properly, and reusing one across sites undoes everything else you do.
- 2
Turn on two factor authentication before you fund anything
An authenticator app is stronger than SMS, because a phone number can be moved to somebody else without your involvement. Turn it on before money goes in, not after.
- 3
Treat anyone who contacts you first as unverified
Support that messages you, an unexpected reward, a person offering to recover funds. Check the contact against the verifier before you answer, and never share a code or a recovery phrase with anybody, including anybody claiming to be us.
- 4
Check the address bar, not the message
A link in a message is the easiest thing in the world to fake. Reach the site the way you normally do, and confirm the domain against the verifier if you have any doubt.
What we do not publish
Named rather than left out. If any of these is attributed to Crpko somewhere, it did not come from us.
- Security certifications
Crpko does not claim ISO 27001, SOC 2 or any equivalent on this site. Where a certification exists it will be named here with its scope and its date, because a badge without either tells you very little.
- Proof of reserves
No reserve attestation is published. This is the strongest thing an exchange can show and the hardest to fake, and until there is one this page will say there is not.
- Independent audits and penetration tests
No audit report or test summary is published. If one is commissioned, what it covered and when belongs here rather than in a sentence about being independently audited.
- Insurance
No insurance arrangement is claimed. Cover of this kind is specific about what it protects and what it excludes, and a general reassurance is not a substitute for those details.
- Regulatory registration
No registration is asserted on this site. Where one applies it will be stated with the registering body and the number, so it can be checked against that body rather than taken from us.
Questions
Not as far as this site claims. No ISO 27001, no SOC 2, no published audit and no reserve attestation. If you have seen any of those attributed to Crpko somewhere else, it did not come from us, and the contact verifier is the way to check whether the source was really ours.
To Sumsub, the third party that carries out verification. They perform the checks and return the result to us. The KYC page sets out what is submitted and what comes back.
Put the email address, handle, domain or number into the contact verifier. Anyone who reaches out first is worth checking, and we will never ask you for a password, a one time code or a recovery phrase.
Use a password that exists nowhere else, and turn on two factor authentication before you fund the account. Between them they stop the great majority of account takeovers, and neither depends on anything we do.
This page describes what Crpko publishes and what it does not. It is not a security guarantee, and it is not investment advice. See our risk disclosure.

