generated: '2026-08-17' method: searched source: https://www.bitstack-app.com/en/regulatory-documents-hub docs: - https://www.bitstack-app.com/en/regulatory-documents-hub - https://www.bitstack-app.com/en/security - https://www.bitstack-app.com/en/terms-and-conditions note: >- Bitstack's conformance posture is REGULATORY, not technical. It holds real, named financial licences and publishes the mandatory policy documents that go with them, but it publishes no API, therefore no API-level standard (OAuth2, OIDC, RFC 9457, pagination, idempotency) can be asserted either way. Every API-standard row below is recorded as not-applicable rather than false, so an absent API is not read as a failed one. No security certification (SOC 2, ISO 27001, PCI DSS) is claimed anywhere on the site; the security page says only that "our platform is regularly audited by IT security experts" without naming an auditor, scope, or report. legal_entity: Bitstack Digital Assets SAS registration: Aix-en-Provence Trade and Companies Register no. 899 125 090 registered_office: 100 impasse des Houillieres, 13590 Meyreuil, France licenses: - id: amf-casp authority: Autorite des Marches Financiers (AMF), France type: Crypto-Assets Service Provider (CASP) number: A2025-003 conforms: true evidence: >- Published on the regulatory documents hub and site footer. Authorized activities: exchange of crypto-assets for funds; exchange of crypto-assets for other crypto-assets; execution of orders for crypto-assets on behalf of clients; custody and administration of crypto-assets on behalf of clients; transfer services for crypto-assets on behalf of clients. - id: acpr-emi-agent authority: Autorite de Controle Prudentiel et de Resolution (ACPR), France type: Agent of an electronic money institution number: '747088' conforms: true evidence: >- Licensed as an agent of Xpollens, an electronic money institution authorized by the ACPR (CIB 16528, RCS Paris no. 501586341). standards: - id: mica-casp conforms: true evidence: AMF CASP authorization A2025-003 covering the five MiCA crypto-asset service activities - id: gdpr conforms: true evidence: GDPR and CNIL compliance stated on the security page and in the privacy policy - id: psd2-emi-agency conforms: true evidence: ACPR-registered agent (747088) of the electronic money institution Xpollens - id: tls conforms: true evidence: TLSv1.3 with HSTS max-age 31536000 observed on www.bitstack-app.com (security/bitstack-domain-security.yml) - id: soc2 conforms: false evidence: no SOC 2 report or Type I/II claim published anywhere on the site - id: iso-27001 conforms: false evidence: no ISO 27001 certification claimed - id: pci-dss conforms: false evidence: no PCI DSS claim; card issuing/processing is delivered through the Xpollens partnership - id: oauth2 conforms: null evidence: not applicable - no public API and no published securityScheme of any kind - id: openid-connect conforms: null evidence: not applicable - /.well-known/openid-configuration returns 404 on every host - id: rfc9457-problem-details conforms: null evidence: not applicable - no public API contract to inspect - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every host (well-known/bitstack-well-known.yml) - id: a2a conforms: false evidence: no agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host published_policies: - Warnings about risks - Customer complaints policy - Conflict of interest management policy - Best execution and order management policy - Retention policy - Commercial policy - Sustainability indicators / adverse climate and environmental impacts disclosure security_partners: - name: Xpollens role: electronic money institution principal (card and cash account issuing) - name: Tink (a Visa subsidiary) role: banking credential storage, approved by the Swedish FSA under number 556898-2192 security_controls_claimed: - AES-256 encryption at rest, TLS in transit - multi-signature key scheme for custody - servers located in Belgium with 24/7 physical security - policy engine for transaction approval controls - periodic third-party IT security audits (auditor not named)