Download the App Download now →
Registered with the Bank of Spain · VASP D803

Security and compliance, by design

AhoraCrypto operates under a strict regulatory framework and applies technical, operational and organisational controls built to protect your funds, your data and your experience.

Regulator
D803
Bank of Spain VASP register
Custody risk
0
Non-custodial · you hold the keys
Monitoring
24/7
Continuous detection & response
Compliance
GDPR
EU data protection · MiCA-ready
A regulated and supervised entity

Registered VASP with the Bank of Spain

AhoraCrypto, S.L. is registered as a Virtual Asset Service Provider (VASP) with the Bank of Spain under number D803, in accordance with Law 10/2010 on the prevention of money laundering and terrorism financing.

The registration places us under the supervision of SEPBLAC (Executive Service of the Commission for the Prevention of Money Laundering) and binds us to identification, due diligence and reporting obligations. We also align our operations with internationally recognised standards for information security, risk management and operational resilience.

Banco de España
VASP Registry
D803
Official VASP registration number
  • Spanish Law 10/2010 (AML)
  • SEPBLAC supervised
Verify on the Bank of Spain website

How we protect you

Defence in depth, from your wallet to our infrastructure.

AhoraCrypto
Your wallet
Private keys stored

Non-custodial by design

We never store your private keys. Crypto goes straight from our platform to your own wallet. Before the first transfer to an external address, we verify ownership of the destination wallet.

TLS handshakeok
TLS 1.3AES-256at-rest

Encryption in transit and at rest

All sensitive data is transmitted and stored with industry-standard encryption. Browser-to-server communications run over modern TLS.

487209
Verification code

Two-factor authentication

Adds a second layer on every login and operation. Internally, least-privilege access and multi-factor on critical systems.

API99.99%
Socket100%
KYC99.97%
All systems normal
24 / 7

Continuous monitoring

The platform is monitored around the clock to detect anomalous activity. Formal incident management and response procedures in place.

Penetration testPASSED
External auditPASSED
Code reviewPASSED

Regular security testing

We carry out audits and security tests regularly, including independent exercises that probe our systems against real-world threats.

#3F
#40
#41
#42
0xa4f3...8d21· verified

Verifiable on-chain

All crypto operations are confirmed on the corresponding blockchain. Transparent, traceable and immutable.

Primary
Replica
Backup

Business continuity, tested

We maintain business continuity and disaster recovery plans, tested regularly to minimise service impact in exceptional scenarios.

AML & KYC

Anti-money laundering & know your customer

We comply with Spanish and European regulations on the prevention of money laundering and terrorism financing.

  • Identity verification (KYC)
    Document and biometric check with proof of life, before any operation is enabled.
  • Sanctions and PEP screening
    Against international sanctions lists (UN, EU, OFAC) and politically exposed persons.
  • Continuous transaction monitoring
    Pattern detection for anomalous and potentially suspicious operations.
  • Travel Rule compliance
    Reporting obligations on crypto transfers under applicable European regulation.
Data Protection

Your data, your rights

We comply with the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). Lawful, fair and transparent processing, only what is needed to provide the service and meet our legal obligations.

Access
Request a copy of your data anytime.
Rectification
Correct inaccurate or incomplete data.
Erasure
Request deletion of your data.
Portability
Take your data elsewhere.
We notify the Spanish Data Protection Agency (AEPD) within the legal 72-hour window for personal data incidents, and the affected individuals where required. We never sell your data to third parties.

Governance and internal control

Independent compliance functions and periodic reviews, supervised by the board of directors, which holds ultimate responsibility for risk and compliance.

Customer support and complaints

Formal procedure for handling complaints, with defined timeframes and an auditable record.