Technical Architecture & Risk Controls

Upholding “security first, compliance first,” GIBBOUS anchors its platform on technology innovation and risk management. Through a self-developed four-layer architecture, full-path risk controls, multi-layer wallet security, and global infrastructure, we offer low latency, high reliability, and transparent compliance.

Four-Layer Architecture

Matching Engine

Lock-free/low-lock data structures and in-memory matching; millions of resting orders per shard and tens of thousands of matches per second with millisecond-level completion.

Wallet Security

MPC/TSS with hot-warm-cold tiering for distributed key management and secure signing.

Compliance Modules

Integrated identity verification (KYC), sanctions screening, AML monitoring, and suspicious-activity reporting across jurisdictions.

Global Acceleration

Anycast networking, cross-region private lines, and distributed nodes for lower latency and consistent access.

This design balances high performance, strong consistency, and auditability—scaling fast while staying compliant and robust.

Risk Control System

KYC Reviews

Ensuring lawful, compliant sources of funds.

AML Mechanisms

Rule engines + behavioral modeling to screen risky activity and file regulatory reports.

Market Integrity Monitoring

High-frequency surveillance and algorithmic detection to block wash trading, self-trading, and manipulation (pump-and-dump), preserving fairness.

The framework meets U.S. MSB and Dubai DMCC requirements while aligning with European and APAC standards for cross-market consistency.

Wallet & Asset Security

Tiered Hot/Warm/Cold Wallet Strategy:

  • Hot: ≤5% for routine small transactions and withdrawals
  • Warm: 15–25% for mid-size settlements and transit
  • Cold: ≥70% stored offline with manual review and batch processing

MPC/TSS:

Distributed signing and multi-party authorization remove single-key risks.

Key & Access Controls:

HSM custody plus multi-role approvals for any fund movement.

On-Chain Risk Controls:

Address risk scoring, fund flow tracing, and blacklist synchronization in real time.

Every fund operation benefits from multi-layer protection.

Global Infrastructure

North America (U.S. East/Central):

Trading & compliance hubs

Middle East (Dubai DMCC):

Regional compliance trading center

Europe (Frankfurt/Amsterdam):

Cross-border clearing & data nodes

APAC (Singapore/Tokyo/Hong Kong):

HFT and regional access points

LATAM (São Paulo):

Emerging-market expansion node

With active-active architecture and disaster recovery, we target 99.99% monthly availability, RTO ≤ 15 min, RPO ≤ 60 sec, enabling rapid failover and protection even under extreme conditions.