Security

Security at Blox

Security is not a feature we added — it is the foundation everything else is built on. Our platform processes $3B+ in digital assets, and every layer of our infrastructure is designed with a zero-trust architecture and defense in depth.

Defense in depth

We implement five independent security layers. Perimeter defense includes web application firewall, DDoS protection, rate limiting, and IP filtering. Network security uses VPC isolation, security groups, network ACLs, and private subnets. Application security enforces two-factor authentication, role-based access control, input validation, and content security policy headers. Data security applies AES-256-GCM encryption at rest, TLS 1.3 in transit, MPC key management, and nonce-based replay protection. Monitoring runs anomaly detection, automated incident response, immutable audit logging, and self-healing health checks.

Threat intelligence

Our proprietary Akamira engine screens against 1M+ threat indicators from 29 integrated intelligence sources covering sanctions, phishing, malware, ransomware, and real-time threat feeds. Machine learning models provide risk scoring with 60% fewer false positives than industry averages. Every wallet, every transaction, and every counterparty is scored in real-time.

Compliance

Our infrastructure is SOC 2 Type II ready with OFAC SDN, EU, UK HMT, and UN sanctions lists updated daily. We provide complete KYC/AML verification workflows, transaction monitoring with configurable alert rules, and exportable audit reports for regulators across multiple jurisdictions. For our AI Agent Pay platform, KYA (Know Your Agent) provides declared purpose, risk categorization, and full audit trails for every autonomous transaction.

Responsible disclosure

If you discover a security vulnerability in any Blox system, please contact us immediately at security@blox.global. We appreciate responsible disclosure and will work with you to address any issues promptly.