Trust & Verification
A marketplace only works if both sides can trust it. Here is exactly how KOLBridge verifies claims, what we protect, and — just as important — what we don't do.
For exchanges: how volume is verified
Every KOL badge on KOLBridge maps to one of two proof tiers. A KOL with no badge has not been verified — we never imply otherwise.
Verified against the exchange's API
The KOL connects a read-only affiliate API key (Bybit, Bitget, Binance, OKX, KuCoin, Gate.io, MEXC, and BingX today; other exchanges stay manual-proof only). At verification time we pull their affiliate volume live from the exchange's own API and record it with the check date. Keys are used for that check and are never stored. Step-by-step key guides live on Support.
- Volume comes from the exchange, not from a screenshot
- Read-only keys — no trading or withdrawal permissions
- Keys are never persisted after the check
Human-checked evidence
The KOL uploads evidence — affiliate dashboard exports, statements, or reports — and an admin reviews it before any badge is granted. Approval is gated behind an admin-only secret; KOLs cannot grant themselves a badge.
- Evidence reviewed by a human before approval
- Weaker tier than API-verified — and labeled as such
- Rejected submissions get no badge at all
Verification is point-in-time. A badge means the volume was checked on a specific date — which is shown alongside it. We do not claim continuous monitoring, and a KOL's numbers can change after verification. Treat the date as part of the proof.
For KOLs: what we protect
Proving your volume shouldn't mean exposing your business.
Proof stays private
Your uploaded evidence is used only for verification. The server strips proof files from every public API response — exchanges see your badge and tier, never your documents.
Contact is gated
Your contact details are hidden until you approve each access request yourself. No approval, no contact — full stop.
You set the price
You choose your own contact fee. Exchanges see the total cost before they send a request, and you decide who gets through.
Platform security
The basics, done properly — no security theater.
Passwords are hashed
Stored as bcrypt hashes. We can't read your password and neither can anyone who reads the database.
httpOnly session cookies
Sessions use httpOnly JWT cookies, so page scripts can't read your session token.
Admin-gated verification
Badge approval requires an admin secret. There is no self-serve path to a verified badge.
Database persistence
Accounts, profiles, and access requests live in a database — not in your browser.
What KOLBridge does not do
Trust also means being clear about our limits.
No custody of funds
We never hold, move, or touch anyone's money. Deals and payouts happen directly between KOLs and exchanges.
No Stripe / card checkout
Paid plans settle on Solana. While you pay, the site watches for your transfer and activates your plan when it matches — point-in-time RPC checks, not continuous chain indexing, and no card processor.
No continuous monitoring
Verification is a dated, point-in-time check. We do not track a KOL's volume in real time after verification.
No badge without proof
If a KOL hasn't passed API or manual verification, they carry no badge. We don't sell badges and a paid plan alone never grants one.
Questions about trust?
Ask us directly — we'd rather explain than overclaim.