Account and website security
Your account holds personal details and a connection to your exchange, so we treat it the way a bank treats a customer login. This page sets out the nine protections that matter most, what each one does, what we ask of you and what happens if something goes wrong. Security reduces risk but cannot remove it, which is why the final points explain how to reach us quickly.
1. Two-factor authentication
Two-factor authentication (2FA) asks for a second proof of identity on top of your password. We support two methods: a time-based code from an authenticator app on your phone, and a six-digit code sent by text message. We recommend the authenticator app because text messages can be diverted if a mobile number is hijacked, a type of fraud known as SIM swapping. Whichever method you pick, the code changes every time and works only once.
You can switch 2FA on during registration or later in your security settings. It is optional for browsing the dashboard and simulator, but it is required before you can connect an exchange, create an API connection or request your first withdrawal. If you lose your phone, you can use the backup codes shown when 2FA was set up, or follow the account recovery steps in point 6.
2. Encryption of your data
Everything that travels between your device and our servers is protected by TLS encryption, and the site is served over HTTPS only. Older, weaker protocol versions are switched off, so a connection that cannot be encrypted properly is refused rather than downgraded.
When data is stored it is encrypted as well. Personal details, uploaded identity documents and exchange credentials sit in encrypted storage, and the keys that unlock them are held separately from the data itself. Passwords are never stored in readable form; only a salted hash is kept, so even our own staff cannot see your password. The platform security team is responsible for these systems, and access to them is limited to named people and logged.
3. Protection against fraud and phishing
Criminals copy trusted brands to trick people into handing over passwords. The only official website is aureo-flowdex.org and the only official sender address is [email protected]. If a link, website or message uses a different spelling, treat it as suspicious and do not sign in.
To make genuine emails easy to recognise, you can set a personal security phrase in your account. Every email we send contains it, and an email without it is not from us. We will never ask for your password, a one-time code, a recovery phrase or remote access to your computer, by phone or in writing. Our Fraud warning page lists the tricks we see most often.
4. Login alerts
We email you whenever a device we have not seen before signs in to your account, when your password or 2FA settings change, when an API connection is created and when a withdrawal is requested. If you enable browser notifications, the same alerts appear as push messages on the device you choose.
Each alert carries the time, the approximate location and the type of device, together with a one-tap link to freeze the account if it was not you. Activity that looks unusual for your account, such as repeated failed logins from several countries, can also trigger a temporary lock until you confirm it is really you.
5. Device and session management
Your security settings list every active session with its browser, device type, approximate location and last activity. If you spot one you do not recognise, you can end it with a single tap, or end all sessions at once. Changing your password signs out every device automatically.
Sessions also end by themselves. After 30 minutes without activity you are signed out, and a session on a shared or public computer should always be closed by hand with the sign-out button. Leaving a dashboard open on a device other than your own is one of the most common ways accounts are misused.
6. Account recovery
If you cannot sign in because you have lost your phone or forgotten your password, start with the reset link on the sign-in page. If you also have no access to your backup codes, contact support and we will ask you to verify your identity with a live photo check and a document matching the details on the account.
Recovery is deliberately a little slower than a normal login, because anything that is easy for you is easy for a thief. After an account has been recovered, withdrawals to a new destination are held for 48 hours and you receive an alert on every channel on file. We will never restore access over the phone based on answers to questions alone.
7. API key permissions
Connecting an exchange means creating an API key at the exchange and entering it in Aureo Flowdex. Exchanges let you choose what a key may do, and we only ever need two permissions: read (to see balances and orders) and trade (to place and cancel orders). We never need the withdraw permission, and the platform refuses a key that has it switched on.
Where your exchange supports it, restrict the key to our published server addresses as well. Keys are stored encrypted and can be revoked in one click at the exchange, which cuts off access at once whatever happens on our side. Treat a key like a password: do not share it, and delete any key you no longer use.
8. Audit history
The dashboard keeps a readable log of what happens on your account: sign-ins, 2FA changes, exchange connections, API key events, strategy launches and edits, setting changes and report exports. Each line shows the date, the time, the device and the result.
You can view the last 12 months in the dashboard and export it for your records. Behind the scenes we keep a longer, tamper-resistant record of the same events, which our team uses to investigate incidents and which we are required to retain under anti-money laundering rules. Staff access to client records is itself logged, so we can show who looked at what and why.
9. Incident support
If you think your account has been accessed without your permission, use the "Freeze account" button in your dashboard, which stops new strategies and withdrawals immediately, then email [email protected] with the word "Security" in the subject line. If you cannot sign in, request a callback and say that it is a security matter so that it is passed to the security team first.
During support hours we acknowledge a security report within one hour, and outside those hours by the start of the next working day. You then receive an update at least every 24 hours until the matter is closed. If personal data has been put at risk, we notify the Information Commissioner's Office within 72 hours where the law requires it, and we tell affected clients without unnecessary delay.
What none of this covers. These measures protect your account, not the value of your investments. Market losses are a trading risk and are explained on the Risk disclosure page. Cryptoassets are not covered by the Financial Services Compensation Scheme.
See the dashboard for yourself
Open a free account, switch on two-factor sign-in and look through the security settings before you decide anything else.