Your money and your data are protected by several independent layers. This page explains each one, what you control yourself and what to do if something looks wrong.
Sign-in
2FA required
Data
Encrypted
Activity
Logged
Nine safeguards, in plain language
No single control is enough, so we stack them. Each point below says what it is, how it works and what you should do.
1. Two-factor authentication
Every account must use two-factor authentication (2FA). You sign in with your password and a six-digit code from an authenticator app on your phone. A text message code is available as a fallback, but the app is safer because it cannot be intercepted through your phone number.
Because 2FA is mandatory, it cannot be switched off by accident or by someone who has your password. If you lose your phone, you recover access with one-time backup codes, or through the identity-checked recovery process described in point 6.
Do this: save your backup codes offline, not in an email or a notes app.
2. Encryption
Data is encrypted in two places. In transit, everything between your browser and our servers travels over HTTPS with modern TLS, so nobody on a shared Wi-Fi network can read it. At rest, sensitive records such as identity documents and exchange credentials are stored in encrypted form.
Encryption applies to the website, the client dashboard and the systems that hold your records. Access to decrypted information is limited to staff roles that need it, and each access is recorded.
Do this: check for the padlock and the correct address before you sign in.
3. Fraud and phishing protection
Scammers copy trading brands. We publish our official domain, tradexai.org, and our only support address, [email protected]. Anything from another domain claiming to be us is not us. You can also set a personal security code in your dashboard, and genuine emails from us will include it.
We never ask for your password, a 2FA code or your exchange secret key by phone, email or chat. If a message asks for any of these, stop and forward it to us. Our fraud warning page explains cloned companies in more detail.
Do this: type our address yourself instead of following links in messages.
4. Login notifications
When your account is accessed from a new device, a new browser or an unusual location, we notify you by email and, if you have the mobile app, by push notification. The message says when it happened, roughly where from and which device type was used.
Notifications also fire on suspicious activity, such as repeated failed sign-ins or a change of contact details. If the sign-in was not yours, use the link in the message to lock the account and end all sessions at once.
Do this: keep your email address current so alerts reach you.
5. Devices and sessions
The Security section of your dashboard lists every active session with its device, browser and last activity. You can revoke any session with one click, which signs that device out immediately and requires a fresh 2FA code to come back.
Sessions also end by themselves after a period of inactivity, so a forgotten laptop at work or a shared computer does not stay signed in indefinitely. Sensitive actions, such as changing a withdrawal destination, ask you to confirm again.
Do this: review your session list once a month and end any you do not recognise.
6. Account recovery
If you lose access, recovery starts with an identity check: you contact support, confirm details that only you should know and, where needed, send a clear photo of your identity document together with a live selfie. Support compares them with what was verified when you registered.
Recovery is deliberately a little slow and strict. Until your identity is confirmed, the account may be restricted from withdrawals, because an attacker who has only a password and a stolen phone number should not be able to move money in minutes.
Do this: contact support from the email address registered on your account.
7. API key permissions
When you connect an exchange, you create an API key on the exchange and paste it into your dashboard. Keys carry permissions, and you decide which. Read-only lets us see balances and prices. Trade lets the platform place and cancel orders. Withdrawal lets funds be moved off the exchange.
Our guidance is simple: grant read and trade, and never enable withdrawal. With withdrawal disabled, even a leaked key cannot send your money elsewhere. Where an exchange supports it, also restrict the key to our listed IP addresses.
Do this: create a new key for each connection, and delete keys you no longer use.
8. Audit history
Your account keeps an audit log that records sign-ins, exchange connections, changes to strategies and settings, and changes to security options. Each entry has a date, a time and the device type, and entries cannot be edited or deleted by the user or by us.
The log is useful in two ways. You can check that every change was one you made. And if you ever need to raise a complaint or an incident, support can see exactly what happened and in what order.
Do this: skim the log after any change you make, to confirm it was recorded as expected.
9. Incident support
If you suspect unauthorised access, email [email protected] or ask for an urgent callback. Support can lock the account within minutes, end every session and pause automated trading while the matter is reviewed.
After the immediate steps, the case is escalated to the security and compliance team. You will receive a written summary of what was found and what changed, and we will tell you promptly if anything affects your funds or personal data.
Do this: report quickly, and change your email password and exchange keys as well.
Please do not wait for proof. A suspicion is enough to ask us to lock the account, and a locked account can be reopened in minutes once you have been identified.
What is and is not protected
Cash deposits with a member institution may be eligible for CDIC coverage, subject to its rules. Eligible securities held by a member investment dealer may be covered by CIPF, subject to its limits. Crypto and other digital assets are generally not covered by CDIC or CIPF.
This means that security controls reduce the chance of theft or error, but they do not insure your trading results. See the risk disclosure for how market losses work.
Five habits that matter most
Technology covers a lot, but most account takeovers begin with a human slip. These habits close the common gaps.
Use a unique password
A password manager makes a long, unique password for this account effortless, and a reused password is the single most common way accounts are lost.
Keep your phone and apps updated
Your authenticator app is only as safe as the device it runs on, so install system updates when they arrive.
Never share codes
A 2FA code is for you alone. Nobody from our team will ever ask you to read one out, however urgent they sound.
Keep withdrawal off exchange keys
If a key cannot withdraw, a stolen key cannot empty your account.
Tell us early
An odd email or a login alert you did not expect is worth a two-minute message to support. We would always rather hear about a false alarm.
See it for yourself
Register, switch on 2FA in your first session and read your own audit log. Your account manager can walk you through every setting.