3REAL

Security

This page explains, plainly, how account access and fund-movement security work on 3REAL today, and what is still on the roadmap. 3REAL is in public beta — we would rather be precise about current limitations than overstate them.

Account Access

Email + Password Login

Live

You can register and sign in with an email address and password. Passwords are hashed with bcrypt and are never stored or logged in plaintext.

Google Sign-In (Optional)

Live

Google sign-in is offered as a convenience, not a requirement. You can use 3REAL fully with email and password alone — Google is never the only way in.

Email Verification

Live

New accounts must verify their email address before full access is granted. This reduces fake-account and account-takeover risk.

Two-Factor Authentication (TOTP)

Planned

App-based two-factor authentication (e.g. Google Authenticator, Authy) is planned. It is not yet available — do not assume your account has 2FA enabled today.

Recovery Codes

Planned

One-time backup recovery codes for account access, in case you lose access to your email or 2FA device, are planned but not yet implemented.

Funds & Transactions

During beta, every deposit and every withdrawal is reviewed manually by our team before funds are credited or released. We do not yet run fully automated on-chain or bank-feed detection for any supported asset. This is slower than an automated system, but it gives a human checkpoint on every movement of funds while the platform is young.

All balances are tracked through a double-entry ledger — the same accounting method used by banks. Every transaction must balance; no balance can change without a matching journal entry.

Sessions & Infrastructure

  • Sessions use signed, HTTP-only cookies and are invalidated immediately on password change or other sensitive account events.
  • All production traffic is served over HTTPS/TLS.
  • Every login, transaction, and admin action is written to an append-only activity log.
  • Access to KYC documents, ledger data, and admin functions is restricted by role-based permissions.

Your Responsibility

We can secure our infrastructure, but we cannot secure your email account, your device, or your wallet for you. Please:

  • Use a strong, unique password for your 3REAL account and for the email address linked to it.
  • Enable any security features your email provider offers (2FA, login alerts).
  • Never share your password, verification codes, or (once available) 2FA/recovery codes with anyone — 3REAL staff will never ask for them.
  • Double-check wallet addresses and bank details before sending a deposit — on-chain and bank transfers are generally irreversible.
  • Report anything suspicious to support@3real.no immediately.

Whitepaper · About · Back to 3REAL