Skip to content
Security

Institutional-Grade Security

Security comes first at Copper. We align with NIST, ISO 27001, and SOC 2, combining in-depth, regular penetration testing, and continuous security training.

Meet Recognized International Standards

We align our security management framework with the international standards and benchmarks institutions expect, so our practices can be verified rather than taken on faith.

SOC2.svg

SOC 2 Type 2

Security & availability attestation

ISO.svg

ISO 27001

ISO-certified security management system

NIST-2.svg

NIST

Cybersecurity framework alignment

Detect and Respond With Security-First Operations

We build our operations around detection and response, keeping our strategy effective as threats evolve. Regular reporting lets us assess our core controls continuously, so our Security Management team can validate our approach using a risk-based methodology.

  • Regular Penetration Testing

    Internal and independent penetration testing runs across our technology to identify and correct vulnerabilities.

  • Machine Learning–Assisted Incident Response

    Our incident management combines machine learning with our teams' own expertise, so we detect and respond to security events faster.

  • 24/7 Security Operations

    A round-the-clock security operations capability, with dedicated Application Security, Infrastructure Security, Security Architecture, and Assurance teams — plus a team supporting our IT infrastructure.

  • Security Training at Every Level

    Every Copper employee takes regular, mandatory security training, covering phishing and the cyber threats specific to our industry.

  • Transfer Risk With $500M Specie Insurance

    We arrange our insurance coverage in partnership with Aon, choosing policies that fit the risks specific to the digital asset sector:

    • A bespoke Crypto Crime policy
    • $500M of specie market-based insurance, placed in the Lloyd's of London market
    Security Built Into Everything.svg

Govern Security Through Dedicated Committees

Copper's security approach is managed by dedicated committees, each playing an essential role in keeping our operations secure and professional. This structure supports a comprehensive, dynamic approach to risk management and security across the company.

Security Committee

Reports to the Risk & Compliance Committee. Manages information security (InfoSec) risks and related policies, and guides the Board on InfoSec risk management and governance.

Global Financial Crime Governance Committee

Reports to the Risk & Compliance Committee and then to the Board. Promotes a culture of compliance, manages financial crime risks, and ensures adherence to global regulatory standards and industry best practices.

Audit Risk and Compliance Committee

Independent committee reporting directly to the Board, responsible for overseeing Copper's risk management and compliance policies and practices across its global operations, together with the effectiveness of the Company's governance, internal controls and enterprise risk management framework.

See Why Pioneering Institutions Use Copper

Book a demo with a member of our team.