Compliance and security by design
Polish VASP registration
Berillium Tech Sp. z o.o. is registered in the Register of Activities in the Field of Virtual Currencies (Rejestr działalności w zakresie walut wirtualnych) maintained by the Director of the Tax Administration Chamber in Katowice (Dyrektor Izby Administracji Skarbowej w Katowicach) under no. RDWW-526 (entered 15 November 2022), for the following services:
- Exchange between virtual currencies and means of payment
- Exchange between forms of virtual currencies
- Intermediation in the exchanges above
- Operating accounts holding virtual currency on behalf of clients (custodial wallet provision)


Mandatory KYC and transaction monitoring
Berillium Tech Sp. z o.o. requires mandatory KYC/KYB on every new client, in line with the Polish AML Act (Ustawa o przeciwdziałaniu praniu pieniędzy oraz finansowaniu terroryzmu of 1 March 2018), EU AML obligations, and applicable sanctions regimes. This is part of our ongoing AML/CFT efforts to combat financial crime and ensure the compliance of our customers’ operations.
Security built for financial infrastructure
As a payments infrastructure company, our security continually evolves to meet the rigorous standards of the global financial industry. Our security stack was designed for reliability, confidentiality and operational continuity.

Client funds are never mixed with Berillium’s or BigeDirect’s. Assets are fully segregated from operational accounts.
We meet the highest international security standards.
Regular penetration testing by third-party experts.
24/7 infrastructure monitoring and alerting.
Our platform is always on.
Hosted on redundant cloud infrastructure
Quarterly recovery testing and automated failover
Incident response procedures reviewed and rehearsed
Only the authorised people can access the right data.
Multi-factor authentication (MFA)
Multi-signature for payouts validation
Role-based permissions for all users
Session timeouts and device-level security enforcement
Your data stays encrypted and recoverable.
End-to-end encryption in transit and at rest.
Daily backups.
Secure deletion policies aligned with GDPR.