ACCOUNT & PLATFORM SECURITY

Security controls work best when they stay visible.

Use layered authentication, review account activity and contact support quickly when something does not look right.

NINE PRACTICAL CONTROLS

Understand each layer of protection.

Exact technical implementations are confirmed within the platform and provider documentation; this page does not claim an unsupported certification.

  1. 01

    Multi-factor authentication

    Where enabled, sign-in combines a password with an authenticator, code or other supported factor. Recovery requires identity checks; support will never ask for a one-time code.

  2. 02

    Encryption boundaries

    Sensitive data should be protected in transit and at rest within responsible systems. The applicable provider documents the exact standards and scope.

  3. 03

    Fraud and phishing defence

    Use only https://corvenhall-trust.com, verify unexpected communications and never disclose credentials, seed phrases or remote device access.

  4. 04

    Login notifications

    Review email or in-platform alerts about new devices and unusual activity. Contact support through a known channel if an alert is unfamiliar.

  5. 05

    Device and session control

    Inspect active sessions, revoke access from devices you no longer use and sign out on shared computers. Inactivity limits may close sessions automatically.

  6. 06

    Account recovery

    Recovery can require identity verification and temporary limits on sensitive actions. This friction helps reduce takeover risk.

  7. 07

    API permissions

    Where API access is available, separate reading, trading and withdrawal rights. Grant only the minimum permission and revoke unused keys.

  8. 08

    Audit history

    Account records may show logins, connected services and changes to strategies or settings. Review the history after any unexpected notification.

  9. 09

    Incident support

    Email [email protected] from a safe device, explain what occurred and request a temporary account restriction when compromise is suspected.

CANADIAN ASSET CONTEXT

Security is not the same as insurance.

Cash deposits held with a CDIC member institution may be eligible for CDIC protection, subject to its rules and limits. Eligible securities held by a CIPF member investment dealer may be protected if that dealer becomes insolvent, subject to CIPF terms. Crypto-assets and many digital assets are generally not covered by CDIC or CIPF.

Market losses are not insured

CDIC and CIPF have specific mandates. Neither guarantees investment value or protects against ordinary market decline.

If you suspect an incident

  1. Stop interacting with the suspicious message or website.
  2. Secure your email account and change reused passwords from a trusted device.
  3. End unfamiliar platform sessions and revoke unused API keys if accessible.
  4. Contact [email protected] through the official domain.
  5. Keep relevant timestamps and screenshots, but do not forward malicious files.

For impersonation or clone-firm concerns, also read our Fraud Warning.

YOUR NEXT STEP

Build a more considered investment plan.

Request access to review available tools, eligibility and onboarding with a Corvenhall specialist.

Get started with AI-powered trading