Security is our highest priority. Learn how you can protect yourself against identity theft and other security risks.
A personal firewall protects your computer against unauthorized access.
Drive-by downloads may happen when visiting a malicious or vulnerable website, viewing an email message or by clicking on a deceptive pop-up window. Malware is malicious software installed on your computer which has a harmful intent that can, for example, capture your login password, and other personal data. The best way to protect yourself from malware is to exercise caution before installing programs on your computer or opening email attachments.
Several signs can help you determine if an email is legitimate or a spoof. Below are some ways to recognize and protect yourself from fraudulent emails.
Spoof emails (also known as phishing or hoax emails) appear to be from well known companies. An email may claim there is an urgent situation concerning your account, then ask you to click a link to a spoof website to provide personal information. Even if you do not supply information, selecting the link may enable thieves to access your computer, record your keystrokes, and capture your passwords.
Sense of urgency: messages claim your account will be closed or suspended. Spelling errors: obvious errors help spoof emails avoid spam filters. All Kristal emails are sent only from the @kristal.ai domain. Please report any suspicious emails to Kristal Support immediately (support@kristal.ai or +65 92391022).
How we protect our platform, your data, and your investments — from network to endpoint.
Kristal hosts its servers on Amazon Web Services (AWS), with industry-standard security compliances and privacy policies. AWS architecture incorporates data encryption, DDoS mitigation and network management aligned with industry best practices.
All external-facing networks are secured with restricted port-level access behind a Web Application Firewall and DDoS protection for all internet traffic.
Internal networks are hardened and no internet access can directly reach any systems or applications. System-level access is secured over VPN.
Kristal employs secure encryption for data at rest and in transit. All communications are encrypted over Secure Sockets Layer, and all storage media is encrypted.
All end-user devices are password protected and encrypted. Corporate devices are managed and remotely monitored using MDM software to ensure compliance.
Personal data is never used without consent from the data subject. Read more about our privacy policy.
Stringent organizational policies protect device, data and employee security. All employees complete annual security training.
Developers follow documented procedures at every phase. Code is reviewed before execution and automated SAST is performed, following OWASP secure-coding guidelines.
Report it to us immediately — real people, fast responses.