Security
How we protect your account, your data and your funds — in plain language, point by point.
Security touches almost every part of how the platform works, from the moment you register to the moment you request a withdrawal. Rather than one long policy document, we've broken it into the nine areas clients ask about most, each explained in plain language with a practical takeaway you can act on.
1. Two-factor authentication (2FA/MFA)
We support authenticator-app-based two-factor authentication as an additional login step alongside your password. Enabling 2FA is optional at registration but strongly encouraged, and it becomes mandatory before you can request a withdrawal above a set threshold. If you lose access to your 2FA device, recovery is handled through our support team after identity verification — we never disable 2FA on request alone, since that is one of the most common ways an account gets taken over.
We recommend setting up 2FA the same day you register, before you make your first deposit, so your account is protected from the outset rather than as an afterthought. Your account manager can walk you through setup on the call if you're unsure how to install or configure an authenticator app.
2. Encryption
Data in transit between your browser and our servers is encrypted using TLS. Sensitive data at rest, including identity-verification documents and account credentials, is encrypted using industry-standard algorithms and stored on access-controlled infrastructure. Encryption keys are managed separately from the systems that use them, and access to decrypted data is limited to the systems and staff who genuinely need it to do their jobs — support staff, for example, do not have raw access to your stored documents.
We also encrypt automated backups of account data, and access to backup systems is restricted in the same way as access to production data. Where legally required, we can provide confirmation of our encryption practices to clients on request, without disclosing implementation details that would weaken the protection itself.
3. Protection against fraud and phishing
We only ever communicate from our official domain and verified support email address, and we will never ask you for your password or your 2FA codes over the phone or by email. Official platform messages include a verification cue you can check against your account settings. If you receive a message claiming to be from us that asks for credentials, treat it as fraudulent and report it — see our Fraud warning page for how to recognise clone websites and impersonation attempts.
We periodically remind clients, through the platform and by email, never to share a one-time code or password with anyone. If you're ever unsure whether a message is genuinely from us, don't click any links in it — navigate to the platform directly and check your account notifications instead.
4. Login notifications
You receive an email alert whenever your account is accessed from a device or location we haven't seen before. These alerts include the approximate location and device type, so you can quickly tell a legitimate login from a suspicious one. If you don't recognise a login, you can revoke that session immediately from your account settings and should contact support to review recent activity.
These alerts are sent automatically and cannot be disabled for logins from genuinely new devices, since they're a core part of how we help you catch unauthorised access quickly. If you travel frequently or regularly use a VPN, you may see more frequent alerts than usual; that's expected and not a sign of a problem.
5. Device and session management
Your account settings show every active session, including device type, approximate location and last activity time. You can revoke access to any session remotely, which immediately signs that device out. Sessions also expire automatically after a period of inactivity, and you're required to re-authenticate for higher-risk actions such as changing your withdrawal details, even within an active session.
We recommend reviewing your active sessions periodically, particularly if you've used a shared or public computer to log in, and revoking any session you don't recognise straight away. Session timeouts are set at a level intended to balance convenience with security, and cannot be extended indefinitely for higher-risk actions.
6. Account recovery
If you lose access to your account, recovery always goes through an identity-verification step with our support team rather than a simple email link, precisely because email links can be intercepted. Depending on the situation we may ask for a government ID matching your account details, and in some cases we apply a short security hold on withdrawals immediately after a recovery, to give you time to notice if something is wrong.
The exact documents requested during recovery depend on the circumstances and the account's verification level. We deliberately make recovery slightly slower than a same-session action like a password reset, because that extra step is one of the more effective ways to stop an attacker who has only partial access to your information.
7. API key permissions
If you connect an external exchange account, the API key we ask you to create should only ever have read and trade permissions enabled — never withdrawal permissions. We do not need, and will never ask for, an API key that can move funds off the connected exchange. Scoping the key this way means that even in the unlikely event of a leak, funds cannot be withdrawn through that key.
If an exchange's key-generation screen only offers a single combined permission set rather than granular scopes, ask your account manager before connecting it — in some cases a different account type or a different exchange configuration is needed to keep the connection properly scoped.
8. Audit history
Every login, connection change and strategy or settings update on your account is logged and visible to you. This audit trail lets you confirm exactly what changed, when, and from where, which is useful both for your own peace of mind and if you ever need to work with support on a disputed action.
Your audit log is retained for a set period and available to you at any time from your account settings; a summary can also be requested from support for a specific date range if you need it for your own records. We recommend a quick periodic glance at your audit log as good account hygiene, much like reviewing a bank statement.
9. Incident support
If you suspect unauthorised access to your account, contact [email protected] immediately. We can place a temporary hold on withdrawals while we investigate, walk you through securing your account, and escalate to our compliance team where warranted. Typical first response time for a reported security incident is under one hour during support hours; outside those hours a report is actioned first thing the next business day.