Skip to content
Bullish UK
Security

How we protect your account and your documents

Funding an account means trusting us with an identity document and a balance. This page sets out the specific controls behind both, rather than asserting that security is a priority.

Documents never get a public URL

Identity documents are written to a private disk outside the web root and streamed to authorised reviewers through an access-controlled route, with sandboxing headers that stop a browser from executing anything it is handed.

Email ownership is proven twice

A one-time code confirms your address before the account is created, and again before any password reset completes. A reset request alone changes nothing.

Every balance change is a ledger row

Credits and debits are written inside a database transaction with the balance row locked, so two simultaneous operations can never produce a figure that does not reconcile.

Rate limits on everything that matters

Sign-in, registration, code requests and password resets are individually throttled, which makes credential stuffing and code guessing impractical rather than merely slow.

Identity documents

What happens to your passport photo

The most common and most reasonable question about verification. Here is the full path the image takes.

  1. 01

    Read in your browser

    Text extraction runs locally on your device. The fields are populated before the image is uploaded, and you edit anything that was misread.

  2. 02

    Stored off the web root

    The file is written to a private disk that nginx cannot serve. There is no URL that returns it, guessable or otherwise.

  3. 03

    Streamed to reviewers only

    An authorised reviewer fetches it through an access-controlled route that sends nosniff and a sandboxing content-security-policy, so nothing in the file can execute.

  4. 04

    Retained, then removed

    We keep it for the period our AML obligations require, then delete it. The retention period is set out in the privacy policy.

Full detail in our privacy policy and AML & KYC policy.

Your side

The part we cannot do for you

Most crypto losses do not involve a broken platform. They start with a compromised email inbox, a reused password or an address pasted from the wrong place. These four habits close the gaps that attackers actually use.

Read the full checklist
  • Secure the inbox first

    Your email address can reset your password. Put a unique password and an authenticator app on it before you worry about anything else.

  • Never reuse your password here

    Credential stuffing works because passwords are reused. A password manager removes the need to remember a unique one.

  • Check withdrawal addresses character by character

    Clipboard-hijacking malware swaps addresses silently. Verify the first and last six characters every time; a broadcast transaction cannot be reversed.

  • Treat urgency as a warning sign

    We will never ask for your password, a verification code or a transfer to a "temporary" address. Anyone who does is not us.

Reporting a security issue

If you believe you have found a vulnerability, email support@bullish.jo3.org with enough detail to reproduce it. Please give us a reasonable window to respond before disclosing publicly, and do not access, modify or exfiltrate data belonging to other members while testing. We will confirm receipt and keep you informed of the outcome.

Verified accounts, auditable balances

Create an account, verify your identity and choose a plan. Your first daily credit lands the day after your plan is activated.

Add to your home screen

Works offline ยท opens full screen

  1. 1

    Tap the Share button in the browser toolbar.

  2. 2

    Scroll down and choose Add to Home Screen

  3. 3

    Tap Add, then open Bullish UK from your home screen.

On iPhone and iPad this is the only way to install a web app โ€” Apple does not let any browser, including Chrome, show an automatic install button.