Trust & Verification

A marketplace only works if both sides can trust it. Here is exactly how KOLBridge verifies claims, what we protect, and — just as important — what we don't do.

For exchanges: how volume is verified

Every KOL badge on KOLBridge maps to one of two proof tiers. A KOL with no badge has not been verified — we never imply otherwise.

API-verified

Verified against the exchange's API

The KOL connects a read-only affiliate API key (Bybit, Bitget, Binance, OKX, KuCoin, Gate.io, MEXC, and BingX today; other exchanges stay manual-proof only). At verification time we pull their affiliate volume live from the exchange's own API and record it with the check date. Keys are used for that check and are never stored. Step-by-step key guides live on Support.

  • Volume comes from the exchange, not from a screenshot
  • Read-only keys — no trading or withdrawal permissions
  • Keys are never persisted after the check
Manually reviewed

Human-checked evidence

The KOL uploads evidence — affiliate dashboard exports, statements, or reports — and an admin reviews it before any badge is granted. Approval is gated behind an admin-only secret; KOLs cannot grant themselves a badge.

  • Evidence reviewed by a human before approval
  • Weaker tier than API-verified — and labeled as such
  • Rejected submissions get no badge at all

Verification is point-in-time. A badge means the volume was checked on a specific date — which is shown alongside it. We do not claim continuous monitoring, and a KOL's numbers can change after verification. Treat the date as part of the proof.

For KOLs: what we protect

Proving your volume shouldn't mean exposing your business.

Proof stays private

Your uploaded evidence is used only for verification. The server strips proof files from every public API response — exchanges see your badge and tier, never your documents.

Contact is gated

Your contact details are hidden until you approve each access request yourself. No approval, no contact — full stop.

You control access

Requesting contact is free for subscribed exchanges. You still approve or decline every request — no approval, no contact.

Platform security

The basics, done properly — no security theater.

Passwords are hashed

Stored as bcrypt hashes. We can't read your password and neither can anyone who reads the database.

httpOnly session cookies

Sessions use httpOnly JWT cookies, so page scripts can't read your session token.

Admin-gated verification

Badge approval requires an admin secret. There is no self-serve path to a verified badge.

Database persistence

Accounts, profiles, and access requests live in a database — not in your browser.

What KOLBridge does not do

Trust also means being clear about our limits.

  • No custody of funds

    We never hold, move, or touch anyone's money. Deals and payouts happen directly between KOLs and exchanges.

  • No Stripe / card checkout

    Paid plans settle on Solana. Each checkout mints a unique on-chain reference, so your payment is matched to your account and nobody else's — and that transaction can never be reused. Point-in-time RPC checks, no card processor, no stored card.

  • No continuous monitoring

    Verification is a dated, point-in-time check. We do not track a KOL's volume in real time after verification.

  • No badge without proof

    If a KOL hasn't passed API or manual verification, they carry no badge. We don't sell badges and a paid plan alone never grants one.

  • No invented numbers

    We don't publish headline user counts, volume totals, or deal tallies we can't evidence. If a figure appears on this site, it came from the database or an exchange API — not a marketing draft.

Questions about trust?

Ask us directly — we'd rather explain than overclaim.