Privacy and Security Commitment
Introduction
As modern financial infrastructure evolves, securely storing, transferring, and managing value requires robust protection across a multi-asset ecosystem. Realising the full utility of these diverse asset categories requires neutralising cyber threats, platform vulnerabilities, and unauthorised data access. Aerapass is committed to safeguarding client privacy and asset integrity by pairing advanced cryptographic controls with operational transparency across all supported asset classes.
Our key initiatives include the following core technical and operational pillars:
- Cryptographic Data Protection. All sensitive customer records and multi-asset transaction data are protected using robust tokenisation and high-grade encryption standards (AES-256 at rest and TLS 1.3 in transit), ensuring data remains unreadable without authenticated decryption keys.
- Identity and Access Management. Strict Role-Based Access Control (RBAC) frameworks, combined with mandatory Multi-Factor Authentication (MFA) and biometric verification, restrict platform and database access strictly to authorized personnel and verified account holders.
- Resilient Infrastructure. Platform applications operate within high-availability, highly compliant cloud environments. Defence-in-depth measures—including automated firewalls, intrusion prevention systems, redundant backups, and automated failover capabilities—safeguard infrastructure resilience against DDoS attacks, service disruptions, and physical outages.
- Secure Development Lifecycle. Systems undergo continuous architecture reviews, static/dynamic code assessments, and automated vulnerability scanning prior to deployment to identify and rectify software bugs or exploits.
- Continuous Monitoring & SIEM. A centralised Security Information and Event Management (SIEM) framework provides real-time logging, threat detection, and proactive security audits to identify anomalies and mitigate emerging operational risks before exploitation.
- User-Centric Privacy by Design. Our platform defaults to a strict data minimisation state, providing clients with transparency and direct control over their transactional data across all asset categories without fear of unlawful surveillance.
- Multi-Asset Regulatory Compliance. Aerapass maintains a comprehensive compliance program aligned with evolving global financial regulations, asset custody standards, AML/CTF mandates, international sanctions laws, and cross-border data privacy standards (e.g., GDPR, PDPA).
Conclusion
Aerapass harmonises multi-asset utility with institutional-grade security and privacy. By establishing continuous threat monitoring, stringent access controls, and transparent governance, Aerapass delivers a safe, compliant ecosystem for global wealth and transaction management.
Have a question?
We’d be happy to chat with you and clear things up for you. Anytime!
Call anytime
Email us
Find us
30c, Morrison Plaza
5-9a Morrison Hill Rd
Wan Chai, Hong Kong
100 Peck Seah St
07-02 PS100
079333 Singapore