Security

Security

Account security, protection of client funds and financial data integrity take precedence over every other product concern.

99.95%

Platform availability over 12 months

24/7

Monitoring of systems and sign-ins

AES-256

Encryption of sensitive data at rest

< 15 min

Target first response time on incidents

Protecting your account

Every access to your account is authenticated, logged and revocable. You stay in control of your devices and sessions.

Encryption

Encrypted transport (TLS 1.3) and encryption of sensitive data at rest.

Authentication

Hashed passwords, strength requirements, rate limiting and 2FA.

Sessions and devices

Session history, remote revocation and sign-out from all devices.

Access control

Roles and permissions enforced server-side, least privilege by default.

Audit trail

Every sensitive action is recorded in an append-only log.

Sign-in alerts

A notification for every new sign-in, new device or sensitive change.

Protecting your funds

Money movements follow a controlled end-to-end process: human review, immutable ledger and daily reconciliation.

Segregated funds

Client funds are held separately from the company's operating funds.

Financial integrity

Immutable ledger, idempotency and reconciliation of movements.

Verified withdrawals

Every withdrawal is reviewed manually and paid only to an account in your name.

Negative balance protection

You cannot lose more than the balance available on your account.

Infrastructure and monitoring

The platform runs on redundant infrastructure, supervised continuously and tested regularly.

Redundant hosting

Load balancing, encrypted backups and tested restore procedures.

Continuous monitoring

Metrics, automated alerting and 24/7 engineering on-call.

Anomaly detection

Analysis of sign-in patterns and unusual account activity.

Backups

Regular encrypted backups with controlled retention.

Compliance and fraud prevention

Identity verification is not paperwork: it protects your account and prevents impersonation.

  • Identity verification (KYC) required before any deposit, trading or withdrawal.
  • Anti-money-laundering (AML) checks and monitoring of atypical activity.
  • Documents stored in private storage with restricted, logged access.
  • Personal data handled in line with GDPR, including access and deletion rights.
  • Internal access is compartmentalised: only authorised agents can open a client file.

Recommended good practice

  1. 01

    Turn on two-factor authentication as soon as your account is open.

  2. 02

    Use a long, unique password that you never reuse anywhere else.

  3. 03

    Always check the website address before entering your credentials.

  4. 04

    We will never ask you for your password or your 2FA code.

  5. 05

    Report any sign-in or transaction you do not recognise immediately.

Incident response

In the event of a security incident our teams follow a defined procedure: containment, analysis, remediation, then notification of affected clients. Compromised access is revoked immediately and sensitive operations are suspended while checks are carried out.

Report a vulnerability

If you believe you have found a security issue, contact our team through the help centre. Please do not disclose it publicly before it is fixed. We acknowledge reports within 72 hours.

Information on this site is neither investment advice nor a solicitation in jurisdictions where such an offer would be unlawful. No regulatory status is claimed until it has been configured and verified.