This thread shouldn't exist.
You pay the guy or you don't, never ever bring inside drama about your business to reddit/here/anywhere it's like the last thing I would ever think of doing.
As for your site UI, the first thing I notice is I have to sign up an account just to look at it. Say what you want about btc-e.com but landing on their front page immediately I can tell what's for trade, see order book, watch trades, (unfortunately watch trollbox too) and no account is needed. To me that is better marketing than being forced to hand over email addresses immediately.
Second, the security information is nebulous.
"Gebbit uses AES-256" means nothing to me. What mode? Because if it's CBC/XTS that's bad
http://sockpuppet.org/blog/2014/04/30/you-dont-want-xts/"Insured wallet" by who? no information
"Security protocols" such as?
Withdraw information is nebulous. How long exactly do withdraws of BTC take. If you're claiming everything is offline then somebody has to physically sign the txn so I'm guessing you have hours of operation (not posted).
One email address "
[email protected]" isn't going to work if say, tomorrow you had 1,000 customers and all their deposits had problems.
There is no information where your corp is, who is running it, phone numbers if my money disappears into a black hole, no bank info, no registration numbers with any known gov ect ect. This can all be excused if there is a multi-sig escrow insurance paid to somebody trusted here, who can hold one signature to ensure users won't have their money stolen should you be hacked out of existence, get shut down, run off with the money ect. So HeroMemberBob and HeroMemberAlice will both hold a sig, and you will hold the other sig to $100,000 in capital put up for insurance. Now we can all trade $100,000 max ceiling and have no worries about your identity (be as anon as you want, who cares). If not, then you have to prove to us why we should trust you with BTC/fiat since we've seen so many exchanges die from incompetence or fraud what makes you different than the idiots who once shut down their ec2 instance and wiped their entire wallet.dat (yes, this actually happened see bitomat.pl).
Also, if you are manually doing txns then add some altcoins, why not. Add all the one's that do multi-sig (I haven't kept up with altcoins, I assume some have multisig).
Even if bitcoins are kept offline, it's still possible to inject site credits and buy coins and withdraw with them. I assume there is some sort of manual accounting/balance sheet going on to prevent this if everything is manual. It is in your competitors interest to sabotage your site and if they can alter the front page, jack the db and start leaking email/passwords, or cause any kind of black PR and uncertainty re: your site security then it's game over so even if somebody "just alters the front page" that's important.
You should also expect attempted breaches by everybody on earth, there is money involved and they will try.
http://homakov.blogspot.ca/2015/01/bitstamp-problem-and-warm-wallets.html