The site's referral record is not registered; the code, benefits and commercial arrangement in the account-opening guide remain unverified. This page hands you a process to run yourself, precisely because a site carrying an unverified referral arrangement should not be handing out verdicts. Full disclosure.
What to check before you put money on any platform
This is not a ranking. It is seven things you can check yourself, each with where to look and what counts as a problem — because in six months the relative positions will have changed and the method will not.
Six of these seven are reading documents somebody else already wrote. Only one costs money — the small withdrawal test — and it is the only one that tests what a platform does rather than what it says, which is why it carries more information than the other six combined.
Why a checklist and not a ranking
Rankings go stale, and the people who publish them usually have an interest. This site takes referral income from an exchange; if we published a "safest platforms" league table, you would be right to ask how the order was arrived at.
A checklist is different. It hands you the method: the same steps work on one platform today and a different one next year, with no need to come back here.
There is also a practical reason. Regulatory status, available regions and proof-of-reserves cadence all change quickly. An article with fixed conclusions starts misleading people within months; an article that says where to look does not.
One — regulatory status
Where to look: the platform's terms or "about" page for a claimed licence or registration number; then look that number up in the issuing authority's own public register.
What counts as a problem:
- The number cannot be found, or the entity name in the register does not match the platform.
- The status shows as revoked, suspended or lapsed.
- The permission scope does not cover the activity you intend to use. A payments registration is not authorisation to run a crypto exchange.
The part most often misread: licence, registration and filing are three different strengths of thing. Registration often means an entity completed a declaration under an anti-money-laundering framework — the regulator knows it exists, not that it examined how it operates. And being licensed in one place is not the same as you being protected where you live.
The correct use of this check is verifying whether what the platform says is true, not deciding which platform is more compliant. The second needs a qualification we do not have. We wrote a separate page on the distinction.
Two — which entity you are actually contracting with
Where to look: the opening paragraphs of the user agreement, for the sentence naming the counterparty.
What counts as a problem: the contracting entity is not the licensed entity, and the terms do not explain the relationship.
People skip this, but it decides whether the previous check meant anything. A brand often operates several legal entities serving different regions. The licence displayed on the website may belong to one of them while the agreement you accept is with another. When something goes wrong, your claim is against the one you signed with.
We hit a concrete version of this while checking fee sources: the same exchange brand runs a global site and a US site as separate entities, with different fee tables and pair-group rules. The fee structures page has the detail. Different entity, different prices, different responsible party.
Three — proof of reserves
Where to look: the platform's proof-of-reserves page.
What counts as a problem: none published; or published without a snapshot timestamp; or the most recent snapshot is old.
How to read it: do not look at the ratio. Look at three fields — the snapshot time and corresponding block height, the verification mechanism, and which assets are covered. Those three decide how much information the statement carries.
More importantly, know its boundary. Proof of reserves tests the asset side at a single instant. It does not cover the platform's other liabilities, does not distinguish owned assets from borrowed ones, does not cover assets outside the listed set, and says nothing about any moment after the snapshot. Treating it as a safety guarantee is the easiest mistake on this list.
Four — the small withdrawal test
How to do it: after depositing, immediately withdraw a small amount. Small enough that the fee ratio looks terrible — the point is not economy.
What you verify at once:
- Whether the withdrawal path actually works, which no document can tell you.
- What additional verification a withdrawal triggers, and whether you can satisfy it.
- Roughly how long it takes, giving you a personal baseline. Later, only deviations from that baseline are worth worrying about.
- The real fee, and whether it matches the published page.
What counts as a problem: withdrawals held without explanation, requests for material unrelated to the withdrawal, or arrival times far outside what the platform itself states.
This matters because historically the earliest visible symptom at platforms that got into trouble showed up in withdrawals, often before any public news. You are not testing this transfer. You are testing the channel.
Five — four clauses in the terms
User agreements are long, but four passages carry nearly all the consequences. Use in-page search rather than reading from the top.
1. How assets are treated in insolvency. Search for "insolvency", "bankruptcy", "estate". The question is whether deposited assets are treated as your property or pooled into the platform's, leaving you a general creditor. This decides where you stand in the worst case.
2. When accounts can be frozen or restricted. Search for "suspend", "freeze", "restrict". Broad discretion here is the industry norm; what you are looking for is whether any timeframe or appeal route is specified.
3. Governing law and dispute venue. Search for "jurisdiction", "arbitration", "dispute". If the specified venue is somewhere you realistically cannot go, or the process costs more than your balance, your paper rights are close to unenforceable.
4. How terms change. Search for "amend", "modify", "notice". "Effective on posting" and "30 days notice for material changes" describe two different relationships.
What counts as a problem: clause one pooling your assets and clause three naming a venue out of your reach. Together those two leave very little you could act on.
Six — support reachability
How to do it: register, do not fund yet, and submit one genuine ordinary question from inside the account.
Record three things: how long until a human replies; whether the reply is a template or addresses your question; and whether there is a route to escalate.
What counts as a problem: no ticket route at all, or no response after several days.
Doing this while you have no money at risk is a completely different experience from meeting support for the first time during an incident. There is also a security dividend: this teaches you where the legitimate support entrance is. Anyone contacting you from elsewhere can then be checked against a known-correct location — which is the single most effective defence available, and it requires no technical skill.
Seven — the public record
Where to look: the platform's own incident announcements or blog, plus public regulatory actions.
How to judge it: having had an incident is not itself a mark against. Any platform operating long enough has had one. What carries information is the handling:
- Was there a public explanation, or silence?
- Were user losses covered, and on what basis?
- Did anything visibly change afterwards, or was there only an apology?
What counts as a problem: the same class of failure recurring with no visible remediation; or a platform with years of operation and a public record that looks suspiciously clean — which usually means it does not publish, not that nothing happened.
How to weight the seven
They are not equal. By information gained per unit of effort:
- The small withdrawal test. The only one that tests behaviour. Cost: one fee. Do it first.
- Terms clauses one and three. They decide your worst-case position. Cost: reading two paragraphs.
- Contracting entity. It determines whether the regulatory check means anything. Cost: three lines.
- Regulatory status. Verifies a claim; not a ranking input.
- Support reachability. Cost: one ticket and a few days.
- Proof of reserves. Informative, narrow, easy to overrate.
- Public record. The most subjective; judge the handling, not the existence.
The reading can be completed in one focused session; support and withdrawal observations take as long as the platform takes to respond. For money you intend to leave somewhere, recording the result is worth the effort. If the balance is temporary, prioritise the small withdrawal test, terms and contracting entity.
One closing note: this list lowers the odds of choosing badly. It does not change the nature of holding assets in someone else's custody. However carefully you run it, it does not replace a judgement about how much should be there at all.
Make the result reproducible
A checklist is most useful when another person, or your future self, can repeat it. Save a compact record for each item: the URL, the date checked, the legal entity named, the exact status you observed and a short note explaining why it passed or needs follow-up. Do not save credentials, account numbers or identity documents in the same record.
For regulator registers and terms, keep the document title and effective date. A screenshot can preserve a public status or clause, but the live source link is still necessary because a cropped image hides context. For proof of reserves, record the snapshot date, covered assets, method and whether your own inclusion check succeeded. For support, retain the ticket identifier and elapsed time, not the support agent's personal details.
The withdrawal test needs the network, destination type, fee shown, submission time and transaction identifier. Record whether any review was announced and whether the arrival matched the estimate shown before submission. A single slow withdrawal is not automatically a platform problem; an unexplained departure from the platform's own message is the fact worth following up.
Put an expiry beside every result. Legal entity and terms should be rechecked after a notice of change; fee and limit pages before the relevant action; proof-of-reserves cadence after the next expected snapshot; support and withdrawal behaviour when a later experience differs from the baseline. A checklist with dates becomes a small evidence file. Without dates it slowly turns into the stale ranking it was designed to replace.
Know what should stop the deposit
Not every imperfection deserves the same response. A missing marketing detail is not equivalent to a counterparty mismatch. Before starting, define the findings that pause funding: a claimed registration that cannot be found, terms naming an unexplained different entity, a withdrawal route that does not complete or an insolvency clause you cannot accept.
Other findings call for a smaller balance or another check rather than an automatic rejection. A proof-of-reserves list that omits the asset you plan to hold tells you that evidence does not cover that asset. Slow but specific support may be usable for a low-consequence account while still being unsuitable for a business workflow. The response should match what the check actually established.
This prevents two opposite errors: waving through a structural problem because the platform scores well elsewhere, and rejecting a platform because one narrow evidence source is unavailable. A stop condition is strongest when it names the fact, the consequence and what new evidence would resolve it.
Use a short conclusion template: "Observed X on date Y; this affects Z; funding remains paused until W is verified." It keeps a serious finding from being diluted by unrelated positives and makes the next action explicit. If the issue is resolved, append the new evidence rather than replacing the old note, so the record shows both the concern and why the decision changed.
When no stop condition is triggered, the checklist still should not end with "safe". State the remaining exposure and the balance limit it suggests. A platform can pass every available check and still be a custodian whose failure, account restriction or operational error affects you. Sizing is the final control because it limits the consequence of evidence being incomplete.
Set the review date before closing the file. A review triggered by a terms notice, entity change or failed withdrawal is more reliable than a vague intention to check again later.
Questions
A platform says it is regulated. How do I verify that?
Find the licence or registration number it claims, then look that number up in the issuing authority's own public register. Check three things: that the entity name matches, that the status is current, and that the permission scope covers the activity you want. The licensed entity is often not the one you contract with, so compare it against the terms page.
Is the small withdrawal test really necessary?
Yes. It is the only item on the list that tests what a platform does rather than what it says, and the cost is one withdrawal fee. Doing it right after your first deposit verifies that the channel works, what extra verification it triggers, and roughly how long it takes.
Which clauses in the terms matter most?
Four: how assets are treated in insolvency, when the platform can freeze or restrict an account, where and how disputes are resolved, and whether changes to the terms require notice. The first two decide your position when something goes wrong; the last two decide whether you can act on it.
How can I test support before opening an account properly?
Register but do not fund, then submit one genuine ordinary question from inside the account. Record how long a human takes, whether the reply is a template or specific, and whether escalation is possible. Learning this while nothing is at risk is far more useful than meeting support during an incident.
How should I read a platform's incident history?
Having had an incident is not automatically a mark against; what matters is the handling. Look for whether there was a public explanation, whether user losses were covered and on what basis, and whether anything visibly changed afterwards. A platform that has published a post-mortem gives you more information than one that has never published anything.