

Login with username and password
Secure storage of credentials
Access recovery mechanism
Google Authenticator integration
Generation and binding of one-time codes (TOTP)
Login confirmation with a second factor
Ability to enable 2FA as a mandatory layer at the project level
Ability to activate 2FA on the user’s initiative
2FA status management in the personal account
Minimal data set to create an account
No redundant fields at the primary entry stage
Conditional information request system (date of birth, full name, address, etc.)
Data request when limits are reached or certain products are activated
Use of data for compliance, verification, and access regulation
Ability to configure field mandatory status
Management of data request scenarios depending on user type or product
Default languages: Russian and English
Language switching by the user in the interface
Interface logic separated from the text layer
Adding new languages by extending the translation dictionary
No need to change business logic when connecting a new locale
Logging of all sessions and authorizations: IP address, geolocation, device type, User-Agent, login method
Client type detection: browser (desktop / mobile), mobile app, API client
Device fingerprint — binding a device to the user profile
Automatic detection of new devices and atypical geolocation
Security triggers: login from a new device after password change, atypical IP, multiple failed login attempts, email or phone change
User notification when triggers fire (email / push)
Forced session confirmation or blocking on anomalous patterns
Ability for the user to view active sessions and terminate them
IP and device blacklist — manual and automatic addition
Logging of all API requests bound to user, device, and method
Audit tools for user and administrator actions
Multi-level KYC/AML verification
Checks against sanctions lists and AML risks
Restriction of access to investment functions until verification is complete
Risk profiling — investor questionnaire, knowledge and risk-tolerance testing
Status determination: qualified / unqualified
Source of Funds check — form + upload of supporting documents
Limit increases after SoF check completion
Document upload inside the investor risk consent form
Recording of submitted forms and uploaded documents in the system
Display of balance and available assets
User PNL
Balance movement chart
Statuses of requests and operations
Quick access to all key actions from one interface
Overview of active investment products and current participation
Asset list with detail per asset
Balance in the source currency with automatic conversion to any required currency at the current rate
Total portfolio value
Generation of an individual deposit address
Automatic top-up system
Recording of incoming funds and balance update after confirmation
System for working with own wallets on the platform
Integration of fiat top-up methods
Creating a withdrawal request
Error control for user typos when entering details
Withdrawal parameter control
Hot wallet system for automatic withdrawal
Duplicate manual withdrawal system on suspicious activity
Suspicious operation control system
Real-time reflection of request status
Asset conversion inside the platform
Rate retrieval from an external source
Liquidity provider integration
Platform fee application, ability to edit the fee
Slippage configuration
Managed model for calculating the final amount
Exchange reflected in transaction history, balances recalculated after the operation
Unified journal: deposits, withdrawals, exchanges, accruals, charges, investment product operations
Filtering by operation type and period
Detail of each transaction
Showcase of investment offers
Sorting by directions, yield, tags
Primary information in the card, including dynamic yield
Ability to interact with a project directly from the marketplace (invest / withdraw)
Number of users, registrations for the period
Deposits and inflow for day / week / month / year
Total system balance
Balance distribution chart
Clickable user table with search and filtering
Viewing profile, KYC/KYB statuses, transactions
User actions: balance change, yield accrual, risk profile change
Logging of each user’s sessions and authorizations
Report on fund movement and balance changes
Table of all projects, search and filtering
Deleting or closing a project
Standardized listing template: name, description, investment model, target round amount, fundraising parameters
Upload of project, legal, and supporting documentation
Document storage in the project profile, investor access to view
Adding a link to a video hosted on a video platform
Processing withdrawal requests
History of all withdrawals and deposits
Control of incoming transactions, AML checks
Yield accrual by investment directions
Yield accrual for specific users, repayment of investment principal
Hot / cold wallet system
Duplicate manual system after suspicious activity
Setting fees for operations
Managing the list of currencies
Configuring rate sources
Managing asset availability
Table of high-risk users
Display of document review status, search and filtering
Viewing the investor questionnaire and uploaded files
Approval or rejection of documents with a comment, saving decision history
Automatic risk level assignment by built-in triggers
Manual risk profile change in the user card
Restricting user actions at the highest risk status
Automatic enforcement of regulatory requirements when the risk profile changes: document request, function blocking
KYB user checks
AML risk control
Moderation and financial decision journal
Logging of all user and administrator actions on the platform
Automatic generation of accounting reports for platform operations over a period
Structured reports on deposits, withdrawals, accruals, fees
Report export in CSV, XLSX, PDF formats
Automatic sending of regulatory reports to supervisory authorities on a schedule
Manual initiation of export for any arbitrary period
AML reports: list of suspicious transactions, STR forms (Suspicious Transaction Report)
Reports on KYC/KYB statuses of the user base
Audit trail — full change log with timestamps for external audit
Report template configuration for a specific regulator’s requirements
React
MobX
ASP.NET Core 8.0
Entity Framework Core 8.0.3
Hangfire
MailKit and MimeKit
MediatR
Swashbuckle
AWS SDK
Bybit
Coingecko
PostgreSQL
Docker
Serilog