Security
AuraxAI provides clear information, automated analytical tools and personal support. The user retains control over decisions and funds, and should carefully assess risks, costs and own goals before using them.
Nine measures in detail
From login to audit log, here's how your account is protected every day.
1. Two-factor authentication (2FA/MFA)
Double verification is carried out by an authentication application (TOTP codes) or a code sent by e-mail. This is strongly recommended when creating an account and mandatory for certain sensitive operations, such as changing payout settings. If the device is lost, a recovery process overseen by support allows access to be restored after identity verification.
2. Encryption
The exchange between your browser and the platform goes through TLS. Stored personal data is encrypted at rest on the systems that process it, and passwords are stored as hashes, never in plaintext. The scope covers the user area, forms and administrative interfaces.
3. Protection against fraud and identity theft
We only communicate from our official domain and never ask for your password via email or phone. Sensitive messages contain a control code that you can find in the user area. If you are unsure about a message that claims to be from us, please check the correct sender address and write to us directly.
4. Sign-in notifications
Each login from a new device triggers an email notification with the date, time and device type. Unusual activity, such as repeated password attempts, triggers an alert and may temporarily limit subsequent attempts. If you don't recognize the link, change your password and notify support.
5. Device and session management
Your user area lists active sessions with their last used date. You can revoke access to a lost or resold device at any time. Inactive sessions are automatically closed after a period of inactivity, and payment transactions require reconfirmation.
6. Account recovery
Lost access is restored through support, after verifying your identity with the data recorded during registration. This process is deliberately demanding: it protects your account from any attempt to take it over by a third party. Temporary restrictions may apply during verification.
7. API key permissions
Technical connections are based on keys with special permissions: read data, perform operations, withdraw funds. Each key is given the minimum scope required for its function, and keys that allow retraction are subject to additional control. The key can be instantly revoked from your user area.
8. Audit log
Logins, device connections, policy changes, and settings changes are recorded in a history that can be viewed from your account. This log allows you to identify an action you would not have taken and helps us reconstruct the facts in the event of a dispute or incident.
9. Support in the event of an incident
A suspected problem is reported immediately [email protected]. Support can temporarily block the account to prevent any operation, then a clear escalation follows: analysis, regular progress information, restore or close the file. You are notified at every stage, without restarting.
What security actually changes
Three common situations and the exact behaviour of the platform.
An unknown connection appears
You immediately receive an email with the device and time. If it weren't for you: changing passwords takes a minute, revoking sessions is instant, and another factor blocked the intruder without this code anyway. Support is automatically notified of links following a significant change.
Someone asks you for the code
By phone or email, no one will ever ask you for a control code. A caller who does this presents itself as what it is: a phishing attempt. Disconnect, check the number on the contact page and report the incident; the audit log will confirm that no operation occurred.
Your phone is lost
Is your authenticator app there? As soon as possible, from another device, revoke active sessions and notify support: the recovery process verifies your identity before recovery. In the meantime, no sensitive operations can take place, not even with your password.
These three scenarios cover most real incidents. What they have in common: the speed of your reaction is just as important as our mechanisms. An account whose owner responds within an hour loses nothing; an account ignored for a week makes any protection more expensive to renew. When in doubt, over-reporting is always the right choice: verifying a fake incident costs nothing, ignoring a real one is costly.
Identity verification and asset protection
Account security doesn't stop at the password. Above all activation, the identity of each holder is verified against ours KYC/AML policy : piece of official identity, proof of address and live comparison. This step has two purposes: it prevents the creation of an account under a false identity and allows reliable recovery if access is lost, since we know exactly who owns the account.
Funds never circulate in the shadows. Deposits and withdrawals go through regulated payment service providers until the account in the holder's name is verified, and every movement is recorded. Withdrawal to a third-party account is rejected by the design: this is one of the most effective protections against account theft, because even an attacker who would take control of the session cannot divert funds outside the verified circle.
Your part of protection
No technical device can replace three simple reflexes: the word single and long addition, reserved for this account; activation of another postman; and distrust any message that encourages you to click or communicate a code. These three habits neutralize most observed hacking attempts on financial platforms.
To go further, please contact KYC/AML policy which explains how identity verification protects accounts and the site risk warning for the market dimension. If you are in doubt about a message or page pretending to be from us, the department fraud alert identifies reportable behaviors. The personal data mobilized by this protection are treated according to Privacy policy : encryption, limited access and defined retention periods.