Responsible reporting
Security policy
Report a suspected vulnerability without including passwords, private keys, identity documents or other sensitive user data.
The editorial priority is a balanced decision across fees, product access, account security, custody controls and withdrawal testing. Readers checking Switzerland should also document CHF funding costs, the onboarding entity and product-specific restrictions. The primary platform scope is OKX. For an OKX-focused review, separate the fee schedule from the rate displayed in the account, document product-specific access, and save the network, memo and withdrawal controls used in a test transfer. This guide starts with a small, reversible test before any larger transfer or leveraged position.
Contact
Use security@swissokx.com. This address must be configured before production deployment.
Scope
Reports may cover the static site, redirects, scripts, headers and domain configuration. Exchange systems and affiliate destinations are outside this site's control.
Testing limits
Do not perform denial-of-service testing, social engineering, credential attacks, automated account creation or destructive testing.
Safe evidence
Provide the affected URL, observed behavior, reproduction steps and a minimal non-sensitive proof.