Digital Asset Security
Protecting your crypto is a shared responsibility
How We Protect You
- Non-custodial by design: We never hold your crypto. Payments go directly to the service processor — we don't have access to your wallet or private keys.
- Encrypted connections: All data between your browser and our servers is encrypted with TLS 1.3.
- Webhook verification: Every payment confirmation is verified via HMAC-SHA512 signatures to prevent tampering.
- Secure sessions: Authentication tokens are stored as httpOnly cookies — inaccessible to JavaScript, resistant to XSS attacks.
- No credential storage: We don't store passwords, private keys, or seed phrases. Ever.
How You Can Protect Yourself
Wallet Security
- Never share your private key or seed phrase with anyone — NexaLuxury will never ask for it.
- Use a hardware wallet for large holdings. Send only the transaction amount from a hot wallet.
- Double-check deposit addresses before sending. Clipboard malware can swap addresses.
- Verify the network matches (e.g., USDT on TRC20, not ERC20) before confirming.
Account Security
- Use a unique email for your NexaLuxury account.
- Enable 2FA on your email provider (Gmail, ProtonMail, etc.).
- Don't reuse passwords across services.
- Log out of shared or public devices after use.
Phishing Awareness
- Our only domain is zoom.nekkha.com. Bookmark it.
- We will never DM you first on Telegram asking for payment or wallet details.
- We will never ask you to "verify" your wallet by connecting to a third-party site.
- If an offer sounds too good to be true (free crypto, double returns), it's a scam.
Transaction Best Practices
- Start with a small test transaction if it's your first time using the platform.
- Always verify the deposit address shown on the checkout page matches what your wallet displays.
- Don't rush — take a moment to confirm all details before sending crypto.
- Keep your Order ID saved until the transaction is fully complete.
- If anything looks off during checkout, don't send — contact support first.
What To Do If Something Goes Wrong
- Sent to wrong address: Crypto sent to an incorrect address is generally irrecoverable. Always double-check before confirming.
- Sent on wrong network: Contact our support immediately with the transaction hash. Recovery depends on the network and recipient.
- Account compromised: Email us immediately at heythere@nexa.luxury with subject "Account Security". We'll lock the account to prevent further activity.
- Suspicious activity: If you notice transactions you didn't make, contact support right away.
Our Commitment
Security is not a feature we ship once — it's an ongoing practice. We continuously audit our systems, update our dependencies, and monitor for threats. If you discover a security vulnerability, please report it responsibly to heythere@nexa.luxury.