Trust

Security practices

Clients trust us with the evidence of their loss. This page sets out the controls we operate and how to report a weakness. It describes our own implementation and does not assert any third-party certification or audit outcome.

Last updated 24 August 2026

01Case data isolation

The client portal is built so an account can only ever read its own cases, stages, transactions and files. Authorisation is enforced at the data layer rather than only in the interface, so a manipulated request from a browser cannot reach another client’s file. Staff tooling is a separate, separately gated area.

02Evidence storage

  • Uploads are written to private storage that is not publicly listable or linkable.
  • Downloads are served through short-lived, per-request links tied to the requesting account.
  • Data is encrypted in transit, and at rest by the storage layer.
  • Reports are only visible to a client once an analyst releases them to the case.

03Access control

Staff access follows least privilege: analysts see the matters they are assigned, elevated actions are limited to a small set of accounts, and roles are held separately from user profiles so they cannot be altered from the client side. Administrative actions against a case are recorded.

04Account security on your side

  • Use a unique, long password for your portal account, or sign in with a provider you already secure.
  • Never share your portal credentials, even with someone claiming to be our analyst.
  • We will never ask for your seed phrase, private keys or exchange password — any such request is fraud.
  • Verify our contact channels against this website before sending money or documents to anyone claiming to represent us.

05Impersonation and recovery scams

Victims of crypto theft are targeted a second time by fake recovery agents, often using the names of real firms. Our only published channels are cases@bitaps.co, support@bitaps.co and WhatsApp +44 7441 929224. If you are approached by someone using our name elsewhere, tell us so we can act on it.

06Incident response

We monitor for anomalous access, and we maintain a defined path for containment, investigation and notification. If an incident affects your case data we will tell you what happened, what data was involved and what we are doing about it, and we will notify the relevant authority where the law requires it.

07Responsible disclosure

If you believe you have found a vulnerability, email support@bitaps.co with “Security” in the subject line and enough detail to reproduce it. We will acknowledge your report and keep you informed while we investigate.

Please do not access, modify or exfiltrate data belonging to other clients, do not run denial-of-service or spam tests, and give us reasonable time to remediate before publishing. We will not pursue researchers who follow these principles in good faith.

Questions about this document?

Write to support@bitaps.co or contact us at Marken 6, Himmelev, 4000 Roskilde, Denmark.

See also our legal & policy centre.