Trust & Verification
A marketplace only works if both sides can trust it. Here is exactly how KOLBridge verifies claims, what we protect, and — just as important — what we don't do.
For exchanges: how volume is verified
Every KOL badge on KOLBridge maps to one of two proof tiers. A KOL with no badge has not been verified — we never imply otherwise.
Verified against the exchange's API
The KOL connects a read-only affiliate API key (Bybit, Bitget, Binance, OKX, KuCoin, Gate.io, MEXC, and BingX today; other exchanges stay manual-proof only). At verification time we pull their affiliate volume live from the exchange's own API and record it with the check date. Keys are used for that check and are never stored. Step-by-step key guides live on Support.
- Volume comes from the exchange, not from a screenshot
- Read-only keys — no trading or withdrawal permissions
- Keys are never persisted after the check
Human-checked evidence
The KOL uploads evidence — affiliate dashboard exports, statements, or reports — and an admin reviews it before any badge is granted. Approval is gated behind an admin-only secret; KOLs cannot grant themselves a badge.
- Evidence reviewed by a human before approval
- Weaker tier than API-verified — and labeled as such
- Rejected submissions get no badge at all
Verification is point-in-time. A badge means the volume was checked on a specific date — which is shown alongside it. We do not claim continuous monitoring, and a KOL's numbers can change after verification. Treat the date as part of the proof.
For KOLs: what we protect
Proving your volume shouldn't mean exposing your business.
Proof stays private
Your uploaded evidence is used only for verification. The server strips proof files from every public API response — exchanges see your badge and tier, never your documents.
Contact is gated
Your contact details are hidden until you approve each access request yourself. No approval, no contact — full stop.
You control access
Requesting contact is free for subscribed exchanges. You still approve or decline every request — no approval, no contact.
Platform security
The basics, done properly — no security theater.
Passwords are hashed
Stored as bcrypt hashes. We can't read your password and neither can anyone who reads the database.
httpOnly session cookies
Sessions use httpOnly JWT cookies, so page scripts can't read your session token.
Admin-gated verification
Badge approval requires an admin secret. There is no self-serve path to a verified badge.
Database persistence
Accounts, profiles, and access requests live in a database — not in your browser.
What KOLBridge does not do
Trust also means being clear about our limits.
No custody of funds
We never hold, move, or touch anyone's money. Deals and payouts happen directly between KOLs and exchanges.
No Stripe / card checkout
Paid plans settle on Solana. Each checkout mints a unique on-chain reference, so your payment is matched to your account and nobody else's — and that transaction can never be reused. Point-in-time RPC checks, no card processor, no stored card.
No continuous monitoring
Verification is a dated, point-in-time check. We do not track a KOL's volume in real time after verification.
No badge without proof
If a KOL hasn't passed API or manual verification, they carry no badge. We don't sell badges and a paid plan alone never grants one.
No invented numbers
We don't publish headline user counts, volume totals, or deal tallies we can't evidence. If a figure appears on this site, it came from the database or an exchange API — not a marketing draft.
Questions about trust?
Ask us directly — we'd rather explain than overclaim.