Company
Security at Enlow
You trust us with identity documents and asset information. Here is how we protect them — and how to reach us if you find something we missed.
Platform safeguards
Credential Protection
Passwords are stored only as salted, one-way hashes. Password resets go through verified email flows — staff can never see or set your password.
Private Document Storage
Verification documents live on private, access-controlled storage that is not publicly reachable. Only you and authorized reviewers can access them.
Encrypted Transport
All traffic between your browser and our servers is encrypted with TLS. Session cookies are protected against cross-site request forgery.
Human Review Controls
Verification approvals and withdrawal releases require review by authorized staff under least-privilege access, with every action attributable.
How you can protect your account
- Use a unique, strong password that you don't reuse on any other site.
- We will never ask for your password, seed phrase, or private keys — by email, chat, or phone. Anyone who does is an impersonator.
- Check the address bar: only trust pages served from our official domain over HTTPS.
- Double-check withdrawal destination addresses before confirming — on-chain transfers to a wrong address may be irreversible.
Responsible disclosure
If you believe you've found a security vulnerability in Enlow, we want to hear from you before anyone else does. Email [email protected] with "Security Vulnerability Report" in the subject and include:
- A description of the issue and the affected page or endpoint.
- Steps to reproduce, with any relevant request/response details.
- Your assessment of the potential impact.
We ask that you give us reasonable time to investigate and remediate before public disclosure, avoid accessing other users' data, and never use a finding beyond what is needed to demonstrate it. We acknowledge reports within one business day and credit researchers who report in good faith.