Your password
Nobody here asks for your password, by email or by any other route. We don't need it to help with the account.
Security
What we do to protect the account, what falls to you, and what to do if you think someone else has got in.
The account stays closed until the address on it is confirmed
Every deposit and every withdrawal
Nobody here can read yours back to you
How access is lost
In practice, unauthorised access comes from a handful of causes, and each one has an answer. Cracking the encryption isn't one of them.
When another site is breached, the passwords from it get tried against financial accounts. What helps: a password used only here, kept in a password manager.
An email or a message that looks like it came from us and points at a fake sign-in page. What helps: type our address yourself instead of following the link.
A shared or unattended machine with the account still open on it. What helps: sign out when you leave a device that you don't control.
An offer to trade the account on your behalf, or to recover your money for a fee paid up front. What helps: credentials belong to the account holder. We never need them, and neither does anyone legitimate.
Requests
If a message asks for any of the things below, it isn't from us, however it's written.
Nobody here asks for your password, by email or by any other route. We don't need it to help with the account.
We don't ask for card or bank details in a message. If one does, it isn't from us.
There's no release fee, clearance charge or tax to pay before a withdrawal. Anyone asking for one is not us.
We don't ask you to install software, and we don't ask for remote access to your device.
You sign in with your email address and a password. Two-factor authentication is not offered, and there's no authenticator app or hardware key to add. That leaves the password as the whole lock, so a password you've used anywhere else should be treated as gone.
Account holder controls
Each of these answers one of the causes above. Together they cover what can be prevented.
Don't use this password anywhere else. If you've used it before, change it.
A password manager lets you keep a long, different password for every site without memorising any of them.
Reach the site by typing our address instead of following a link in an email. That's how the imitation sign-in pages work.
Sign out on any shared or unattended machine, and don't let the browser save the password on it.
Password resets and account notices go to your registered email address. It needs protecting at least as well as the trading account.
Go through positions, funding history and account details. That's how you spot something unauthorised before anyone tells you.
If it happens
Four things, in order. The first two are yours to do, and they're the ones that matter most.
Do it in Settings if you can still get in. If you can't, use the reset link on the sign-in screen.
Look for any position, deposit or withdrawal you didn't open or ask for.
Write to support@quantivofx.com and set out what you've found.
If someone may have got into your email as well, change that password too. It controls the reset for the trading account.
Enquiries
Forward anything that claims to be from us and we'll tell you whether it is.