Security and trust

Protect the account. Preserve the source. Control the decision.

Crypto Reconcile’s security model combines centrally managed NexTron identity, short-lived one-time product launches, Australian-region operations and explicit approval for financial judgement.

AU

Australian operations

Operational Crypto Reconcile application data is hosted in Australian regions. Public marketing pages contain no customer records.

One-time app launch

NexTron Profile launches CR with a product- and origin-bound code that expires quickly and can be redeemed only once.

ID

Central access control

NexTron remains the authority for users, entitlements, partners, suspension, support and administrative impersonation.

FY

Scope isolation

Application requests carry an explicit Reporting Entity. Calculations and reports are bound to one entity and financial year.

Human approval

Valuation values and tolerance findings stay proposed until the user deliberately accepts the financial change.

Source provenance

Imports, mapping choices, rate sources, explanations and recorded reasons remain available for review.

Direct CR sign-in

Crypto Reconcile owns the experience. NexTron protects the identity.

Direct visitors sign in on the Crypto Reconcile interface using Google, Microsoft or an email link. The underlying identity and entitlement rules remain centrally managed by NexTron IT.

  • No redirect through the NexTron marketing homepage
  • Provider callbacks return through a signed, allowlisted product state
  • CR receives a short-lived, single-use launch code
  • Suspended, closed or unentitled accounts remain blocked server-side
CR
Crypto Reconcile login

User selects Google, Microsoft or email

Branded
ID
NexTron identity service

Validates identity and central entitlement

Controlled
One-time launch ticket

Product, origin and 90-second expiry bound

Single use
APP
Crypto Reconcile session

Protected APIs enforce access again

Verified
Data questions

What users should know.

Does Crypto Reconcile need exchange passwords?

No. The current workflow uses files the user exports from the exchange. Do not send passwords, API secrets or seed phrases.

Can CR change a valuation automatically?

It can retrieve or propose evidence, but a financial valuation change remains subject to explicit user approval.

What happens to archived Reporting Entities?

They become read-only. Historical records and reports remain available according to plan and retention terms.

How do I report a security concern?

Email admin@nextron.com.au. Do not include passwords, seed phrases or private keys.

Crypto Reconcile will never ask for a wallet seed phrase or private key. Do not upload credentials inside a CSV or support message.