Nothing to hold, nothing to lose
The desk does not hold client funds on an ongoing basis. There is no account balance, no stored wallet and no pooled float sitting in your name overnight.
Most security pages are adjectives. This one describes controls, says which of them are principles rather than audited facts, and is explicit about the part of the risk that sits with you rather than with us.
The largest risks in an OTC trade are not exotic. Everything below is organised around those four.
The desk does not hold client funds on an ongoing basis. There is no account balance, no stored wallet and no pooled float sitting in your name overnight.
Money leaves only to a bank account in the same name as the verified client, confirmed before the trade and not changeable inside it.
You sign your own transactions from your own wallet. We never ask for a seed phrase, a private key or remote access to your device, for any reason.
Payments out are prepared by one person and released by a second. No single individual can move client value alone.
The structural point comes first, because it removes more risk than any control could add: the desk does not hold client funds on an ongoing basis. Conexus is not a custodial exchange. There is no account to fund, no balance to leave value in, and nothing that could be frozen, lent out, rehypothecated or lost in someone else's insolvency. Value is in motion during a trade and at rest in your own custody outside it.
In practice a trade has two legs. You send the crypto leg on-chain from your own wallet to an address confirmed with your trader. We send the fiat leg from the desk's bank account to a bank account in the same name as the verified client — in South Africa by EFT, RTC or PayShap, elsewhere on the rail confirmed before the quote. Both legs are documented in a written confirmation carrying the reference, the asset, the network, the rate, the gross and the net.
Several rules exist purely to defeat payment redirection, which is the most common way money is actually lost in transactions of this size — not by cryptography failing, but by a bank account number being swapped in a message:
Blockchain transfers are irreversible. That is a property of the technology, not a policy choice, and no desk, network or recovery service can undo one. The controls above exist because that irreversibility means the only workable place to catch an error is before the send button.
Where a control has not been independently audited, we say so rather than implying a certification we do not hold.
The desk holds crypto assets only transiently, while a trade settles. The principles governing that key material are ordinary institutional practice, and we describe them as principles because you have no way to verify our internal configuration and we are not going to ask you to take a claim about it on faith.
What we will not tell you is which custody products, hardware or providers are in use, where key material physically sits, or what the internal thresholds are. Publishing that would help an attacker plan and would help you not at all. Any firm that publishes its full key architecture on a marketing page has either simplified it into meaninglessness or has made itself a map.
We also will not reach for the borrowed adjectives that decorate most security pages — the ones that attach the word "grade" to a bank or an army, or promise that something cannot be broken. They are not measurements of anything, and a desk that uses them is telling you it has nothing specific to say.
Onboarding a client to an accountable institution means collecting exactly the material a criminal would most like to have: identity documents, proof of address, bank details and source-of-funds evidence. The only responsible way to handle that is to hold as little of it as the law permits, for no longer than the law requires, and to be plain about both. The regime described here is South African, because that is where the desk keeps its records.
Data minimisation. We collect what customer due diligence under section 21 of the FIC Act requires, plus what is needed to settle your trade and account for it. We do not collect data speculatively for marketing, we do not buy or sell personal information, and we do not require an account, a profile or a stored payment method to deal with the desk.
Retention. Records of clients and transactions are kept for five years, as sections 22 and 23 of the FIC Act require. That obligation overrides a deletion request for the records it covers — we cannot delete a transaction record on demand, and no compliant desk can. Material outside that scope is not kept indefinitely.
POPIA. Personal information is processed under the Protection of Personal Information Act 4 of 2013: for a lawful purpose you were told about, with appropriate security safeguards under section 19, and with the rights of access, correction and objection that the Act gives you. The information officer is Information Officer — to be confirmed, contactable at support@conexus-crypto.com. If a security compromise affects your personal information, section 22 requires notification to the Information Regulator and to you, and we will make it as specific as the facts allow rather than as vague as the law permits. You may complain to the Information Regulator (South Africa) directly, and you do not need our permission to do so.
Sharing. Information is disclosed where the law requires it — reports to the Financial Intelligence Centre under sections 28 and 29, information accompanying a transfer under FIC Directive 9 of 2024, requests from SARS or a court, and the OECD Crypto-Asset Reporting Framework, which South Africa adopted from 1 March 2026 with the first return due by 31 May 2027 — and to the service providers we need to operate, under contract. Not to anyone else. What each of those means in practice is set out in the privacy policy and the compliance page.
One consequence worth saying out loud: this desk cannot offer you privacy from a tax authority or a financial intelligence unit, and nobody operating lawfully can. If that is what you are shopping for, no page on this site will help you.
Everything below is checkable from your own browser, which is the point of listing it.
Every request is served over HTTPS, with HTTP Strict Transport Security set for a year including subdomains, so a browser that has seen this site once will refuse to load it insecurely afterwards.
Scripts, styles, images, fonts and connections are restricted by a content security policy. Framing is denied outright, form submissions are restricted to this origin, and object embedding is blocked.
X-Content-Type-Options: nosniff, X-Frame-Options: DENY, a strict-origin-when-cross-origin referrer policy, a permissions policy switching off camera, microphone, geolocation, payment and sensor access, and a same-origin cross-origin opener policy.
The site is a set of static pages. There is no client login, no session to hijack, no stored card and no dashboard holding your balance, because there is no balance.
Strictly necessary cookies only by default. Analytics stay disabled until you turn them on, and they are anonymous page counts rather than a profile of you.
Pricing is drawn from VALR and Luno order books through a cached endpoint on this origin. It moves nothing, holds nothing and is always indicative — a firm rate exists only once a trader confirms it in writing.
You can verify most of that yourself: open your browser's developer tools on any page of this site and read the response headers. We would rather you did that than believed a paragraph about it.
Being candid about this: in transactions of this size, the client side is where losses usually start. Not because clients are careless, but because that is where the attacker has the easier target.
Use a wallet you control. Keep the seed phrase offline and on paper, never in a photo, a password manager note, a cloud drive or a chat. Nobody legitimate — not us, not a wallet vendor, not an exchange — ever needs it.
Check the number, handle and domain against the official channel list on this site, and start the conversation yourself. Confirm banking details and wallet addresses verbally on a call you initiated.
USDT on the wrong chain is the most common self-inflicted loss in this market. Confirm the network out loud with your trader, then check the first characters and the last characters of the address on the device you are sending from.
On any first large transfer, send a small amount, wait for confirmation, and get acknowledgement from the person you expect before the balance follows.
Multi-factor authentication on your email and your exchange accounts, using an authenticator app or a hardware key rather than SMS. Your email is the recovery path for everything else, so it is the account worth protecting most.
A real desk holds a quote for an agreed window and puts it in writing. Pressure to act in the next two minutes is a technique. So is a story about why the usual process has to be skipped just this once.
A seed phrase or private key goes to nobody, ever — not to us, not to "support", not to anyone offering to help. The full list of things Conexus will never do is on the verify our channels page.
If you have found a vulnerability in this website or its endpoints, we want to hear about it and we will not treat a good-faith report as an attack.
Where to send it. Email support@conexus-crypto.com with "Security disclosure" in the subject line. Include what you found, the steps to reproduce it, the affected URL or endpoint, and what you believe the impact is. If you would like to encrypt the report, say so in the first message and we will arrange a key.
What we will do. We aim to acknowledge a report within five business days, tell you whether we can reproduce it, and let you know when it is fixed. We will credit you if you want to be credited and stay quiet if you do not. We do not currently run a paid bug bounty, and we would rather say that than let you spend a week expecting one.
In scope: conexus-crypto.com and the API endpoints served from it.
Out of scope: social engineering of our staff, our clients or our service providers; physical attempts on the office; denial-of-service and volumetric testing; spam or content-injection reports with no security impact; and raw automated scanner output with no demonstrated exploitability. Missing headers or configuration hardening on their own are welcome as observations, but please say what an attacker could actually achieve with them.
What we ask of you. Do not access, modify or store anyone else's data. Do not degrade the service for other users. Do not use a finding to extract funds, and do not attempt to trade or interact with real client transactions. Give us a reasonable opportunity to fix the issue before publishing. Stay within the law that applies to you and to us — good faith is not a defence we can grant you, and we would rather your research stayed clearly lawful.
If instead you have been contacted by someone impersonating the desk, that is not a vulnerability report and it is more urgent: follow the steps on the verify our channels page.
Not on an ongoing basis. Value is in motion only while a trade settles, and outside that it is in your own custody and your own bank account. There is no Conexus balance, no wallet to fund and nothing to withdraw.
We do not publish an insurance claim on this site, because you cannot verify one and an unverifiable claim is worth nothing to you. What we can tell you is structural and checkable: the desk does not hold client funds on an ongoing basis, so there is no pooled balance sitting at risk. Crypto assets are not a regulated deposit and are not covered by any deposit-protection scheme in South Africa.
No, in every circumstance and at every stage. Nobody at Conexus will ever ask for a seed phrase, a private key, a wallet password or remote access to your device. Anyone who does is not us, whatever the number or handle says.
Five years for client and transaction records, because sections 22 and 23 of the FIC Act require it. That obligation is not something we can waive on request, and it applies to every accountable institution in South Africa. Details are in the privacy policy.
Section 22 of POPIA requires notification to the Information Regulator and to affected data subjects where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. We will notify as specifically as the facts allow, including what was affected and what you should do. You can also complain to the Information Regulator directly.
No. Customer due diligence is a legal duty under section 21 of the FIC Act, not a desk policy we can waive for a good client or a large ticket. Any desk offering to skip it is either breaking the law or is not a desk at all.
The exact number, handle and domain — and the things the desk will never do.
Licensing position, FICA, sanctions screening and what gets reported.
What is collected, why, on what legal basis and for how long.
Before you send anything, ask a trader how settlement will work, who authorises the payment out and what documents you get afterwards. A desk worth using answers all three without hesitating.