Resources

Compliance and security by design

Compliance

Registered VASP by the Danish FSA

BigeDirect is committed to working closely and collaboratively with regulators as part of our anti-money laundering and countering the financing of terrorism (AML/CFT) compliance efforts aimed at combating financial crime and ensuring the compliance of our customers’ operations. BigeDirect currently holds the following regulatory authorizations and registrations:

BigeDirect is registered as a Virtual Asset Service Provider (VASP) by the Danish Financial Supervisory Authority (Finanstilsynet) (registration FTID 17532) for the following services:

  • Custodian wallet provider
  • Exchange service between virtual assets and fiat currencies, including the exchange service between virtual currencies and fiat currencies,
  • Exchange service between one or more forms of virtual assets and
  • Transfer of virtual assets.

AML/CFT

Mandatory KYC and transaction monitoring

BigeDirect requires mandatory KYC to be undertaken to onboard any new client in order to comply with legal and regulatory obligations including, but not limited to, rules governing anti-money laundering, counter-terrorism financing and sanctions.

This is part of our anti-money laundering and countering the financing of terrorism (AML/CFT) compliance efforts aimed at combating financial crime and ensuring the compliance of our customers operations.

Security Center

Security built for financial infrastructure

As a payments infrastructure company, our security continually evolves to meet the rigorous standards of the global financial industry. Our security stack was designed for reliability, confidentiality and operational continuity.

Segregated Funds

Client funds are never mixed with BigeDirect’s. Assets are fully segregated from operational accounts.

Certified infrastructure

We meet the highest international security standards.
Regular penetration testing by third-party experts.
24/7 infrastructure monitoring and alerting.

Continuity & resilience

Our platform is always on.

Hosted on redundant cloud infrastructure

Quarterly recovery testing and automated failover

Incident response procedures reviewed and rehearsed

Access Control

Only the authorised people can access the right data.

Multi-factor authentication (MFA)

Multi-signature for payouts validation

Role-based permissions for all users

Session timeouts and device-level security enforcement

Data Protection

Your data stays encrypted and recoverable.
End-to-end encryption in transit and at rest.
Daily backups.
Secure deletion policies aligned with GDPR.

This website stores cookies on your computer. Cookies Policy