Security at VEX Deals

This page lists the security measures actually implemented on VEX Deals — no generic promises. Last verified: 2026-09-27.

Encrypted connections (HTTPS)

Every page is served over HTTPS with HSTS, so data in transit between you and VEX Deals cannot be read by eavesdroppers on the network.

Security headers

Responses carry a strict Content-Security-Policy, X-Content-Type-Options: nosniff, X-Frame-Options, a Referrer-Policy and a Permissions-Policy that blocks camera, microphone, geolocation, payment and USB access for pages on this site.

Rate limiting

The API sits behind an in-memory rate limiter capped at 120 requests per minute per IP address; requests over the limit receive HTTP 429, which slows down brute-force attacks and automated abuse.

Two-step verification (OTP)

Account verification uses a 6-digit one-time code (OTP) delivered through our Telegram bot. Phone-number changes require a request that an administrator must confirm.

PIN lock

Accounts support a PIN lock with a failed-attempt counter. Keep your PIN private — never share it in messages, emails or support chats.

Provably fair lottery (SHA-256)

Lottery draws are built on verifiable SHA-256 hashing so results can be checked independently — see the Provably Fair Lottery guide.

What we never ask for

VEX Deals never asks for bank card numbers or passwords on this platform, and we do not sell personal data — see our Privacy Policy.

Report a vulnerability

If you find a security issue, email support@vex.deals with the steps to reproduce it. Please allow us reasonable time to investigate before publishing details.

AboutContactSecurityPrivacy PolicyTerms & ConditionsResponsible GamblingEditorial PolicyAffiliate Disclosure