Two-factor authentication
Use an authenticator-based second factor where available, store recovery codes offline, and never give one-time codes to support or a caller.
Account security
Security combines account controls, monitored access signals, protected data transport, identity checks, and clear response steps when something looks wrong.
Trade with control
Indicative 50 ms average execution, practical risk controls, and 24/5 support in one connected mobile and web platform. Actual execution varies.
Use an authenticator-based second factor where available, store recovery codes offline, and never give one-time codes to support or a caller.
Account and application data should use encrypted transport and controlled storage. Production implementations require verified configuration, key management, and security testing.
Review recognised devices, browser details, and approximate access context; remove access from devices you no longer control.
Inspect active sessions, sign out remotely where supported, and expect re-authentication after sensitive changes or unusual activity.
KYC and step-up checks may be used for onboarding, recovery, 2FA reset, profile changes, and higher-risk account actions.
If access may be compromised, change the password from a trusted device, end other sessions, preserve evidence, and contact the verified support route.
Type or bookmark the verified platform address; do not trust a search ad or unsolicited link.
Reject requests for passwords, 2FA codes, recovery codes, remote-access software, or full payment credentials.
Treat urgency, guaranteed returns, secret strategies, and pressure to move funds as warning signs.
Confirm funding instructions only inside the authenticated account area.
Report lookalike domains, unusual attachments, or unfamiliar sessions promptly.