QUANTLUX
AustraliaSecurity
Ask which controls are actually available: multi-factor authentication, sign-in notifications, encryption and session management. Their availability must be confirmed with the provider.
Security of your QUANTLUX account
Protecting your account is a joint effort: we provide the technology and you stay in control of your access. This page summarises the available measures and recommended practices. For the full risk context, see the risk information.
Access controls
The first lines of defence sit at sign-in.
1. Two-factor / multi-factor authentication (2FA/MFA)
We support authenticator apps (TOTP) plus verification by SMS and email. We recommend enabling 2FA from day one; it is not required for browsing, but it is for sensitive operations. If you lose your device, recovery is handled by verifying your identity with the support team.
2. Encryption
Data in transit is encrypted with TLS 1.2 or higher (HTTPS). Data at rest is stored encrypted on managed systems with rotating keys. Encryption covers credentials, contact details and activity logs.
3. Fraud and phishing protection
The official domain is quantlux.org. Our communications include a personalised greeting and never ask for passwords or codes. If a message requests remote access or payments to third parties, it is not from us: report it immediately.
4. Sign-in alerts
We notify you by email of every sign-in from a new device and of any unusual activity. Review these alerts: they are the fastest way to spot unauthorised access.
Devices, sessions and keys
Control where the platform connects from and with which permissions.
5. Device and session management
From the dashboard you can view active sessions, review known devices and remotely close any session. Idle sessions end automatically for security.
6. Account recovery
Recovery requires identity verification (registration data + proof of control of your email or phone). Support will never ask for your password. While verification is under way, some functions are limited to protect your funds.
7. API key permissions
Create API keys with the minimum privilege needed: read-only for monitoring, read and trade for operating, and withdrawals only if you genuinely need them. Restrict keys by IP address and rotate them regularly.
8. Audit history
Sign-ins, connections, strategy changes and configuration adjustments are logged with date and device. You can request this history at any time; we also use it to investigate incidents.
9. Incident support
If you notice suspicious activity: 1) change your password from a secure device; 2) close other sessions from the dashboard; 3) email [email protected] with the subject "Incident". If the account is compromised, we may block it preventively while we verify. The team works 24/7 and will keep you informed throughout the investigation via a single communication channel.
No measure removes market risk: security protects access to your account, not the outcome of trades. Review the risk page and the terms of use for the full context.
KEEP READING
Explore the details
MAKE YOUR FIRST STEP A CONVERSATION
Registration open — limited places
Start with your details. A personal contact can explain the platform and help you review the next steps.