Why can’t all security details be published?

Bitpanda Enterprise Custody publishes Help Centre content that explains custody concepts, operational workflows, and user responsibilities at a level suitable for customers and authorised users.

Some security, architecture, infrastructure, and key management details are not published publicly because they may be sensitive. Publishing too much detail about security controls can reduce their effectiveness or create unnecessary operational risk.

What information is suitable for the Help Centre?

The Help Centre is intended to provide practical guidance on topics such as:

  • How users interact with BE Custody
  • General custody concepts
  • Transaction and approval workflows
  • Roles and permissions
  • Operational checks
  • Support and escalation routes
  • Public-safe security guidance
  • Safe handling of credentials, devices, reports, and support information

This information helps users understand how to operate safely without exposing sensitive implementation details.

What information may not be published publicly?

Some information is not suitable for public Help Centre articles, including detailed descriptions of:

  • Security architecture
  • Infrastructure configuration
  • HSM implementation details
  • Key lifecycle procedures
  • Signing architecture
  • Internal operational runbooks
  • Internal access controls
  • Incident response procedures
  • Customer-specific deployment details
  • Controls that could be weakened if disclosed publicly

The exact level of information that can be shared may depend on the audience, the request, the customer relationship, and the approved review process.

Why is some information restricted?

Restricting sensitive information helps protect customers, users, and the custody environment.

It can help reduce risks such as:

  • Targeted attacks against custody infrastructure
  • Misuse of operational knowledge
  • Circumvention of controls
  • Social engineering
  • Exposure of customer-specific security arrangements
  • Unauthorised access to internal procedures
  • Weakening of defence-in-depth controls

This approach is common in institutional security environments, where detailed security information is shared only through controlled channels.

Can customers receive more detailed security information?

Yes, where appropriate.

Bitpanda Enterprise Custody can provide additional security, technical, operational, compliance, or due diligence information through approved review channels. This may involve commercial, legal, compliance, security, or technical stakeholders.

The information shared will depend on the nature of the request, the customer relationship, confidentiality requirements, and the review process.

How should customers request more information?

Customers should raise the request through their approved Bitpanda Enterprise Custody contact or support channel.

When requesting more detailed information, include:

  • Your organisation name
  • The reason for the request
  • The type of review being performed
  • The specific topic or control area
  • Any deadlines or questionnaire requirements
  • The intended recipients of the information

Do not include passwords, PINs, private keys, seed phrases, API keys, API secrets, or other sensitive authentication information in the request.

What if I see sensitive information in a public article?

If you believe a public Help Centre article contains sensitive, outdated, or inappropriate information, report it through the approved internal or support process so it can be reviewed.

Was this article helpful?
0 out of 0 found this helpful