Trust
Platform security, without the theatre.
This page lists the controls that exist. It does not claim the product is risk-free. Investment risk lives on the risk disclosure.
Transport and sessions
The site is served over HTTPS. Session cookies are used after login. Log out on shared machines. The address bar should show exoyield.com — not a look-alike domain from a message.
Passwords and 2FA
Passwords are stored hashed. Two-factor authentication uses a TOTP app such as Google Authenticator. Enable it before the first withdrawal. Do not photograph the QR code into a chat group. If you lose the device, contact support from the verified email before you lose the email too.
Deposit addresses
Each account has a dedicated USDT TRC20 address so incoming transfers can be matched without a shared hot inbox. Still verify the characters you paste. Malware on your own machine can swap an address in the clipboard. That is not a platform bug.
KYC as a limit, not a badge
Unverified accounts stay inside a published investment cap. Verification raises the cap and creates a stronger identity record for abuse review. The desk may ask for documents again if a withdrawal pattern looks inconsistent with the file.
What you still own
You own the security of your email, your authenticator, and the wallet that sends and receives USDT. Support will never ask for your password or 2FA code. Anyone who does is not the desk.
Logged-in users manage 2FA at Security settings. New users should start at Get started.