Skip to content
Demo accounts open with no deposit and no documents · every deposit and withdrawal is reviewed before the money moves · the terminal runs in a browser, on a desktop or a phone
EUR/USD1.08742+0.14%GBP/USD1.27118-0.08%USD/JPY156.284+0.31%XAU/USD2,384.60+0.62%US5005,431.20+0.44%NAS10019,842.7+0.71%GER4018,412.5-0.12%UK1008,204.30+0.19%BTC/USD67,482.00-1.24%ETH/USD3,512.40+2.08%WTI78.42-0.55%AAPL214.29+0.86%TSLA182.63-1.42%EUR/USD1.08742+0.14%GBP/USD1.27118-0.08%USD/JPY156.284+0.31%XAU/USD2,384.60+0.62%US5005,431.20+0.44%NAS10019,842.7+0.71%GER4018,412.5-0.12%UK1008,204.30+0.19%BTC/USD67,482.00-1.24%ETH/USD3,512.40+2.08%WTI78.42-0.55%AAPL214.29+0.86%TSLA182.63-1.42%

Security

Account security, and what it depends on.

What we do to protect the account, what falls to you, and what to do if you think someone else has got in.

Confirmed by email

The account stays closed until the address on it is confirmed

Reviewed before it moves

Every deposit and every withdrawal

Passwords stay unreadable

Nobody here can read yours back to you

How access is lost

Losing an account is rarely a technical failure.

In practice, unauthorised access comes from a handful of causes, and each one has an answer. Cracking the encryption isn't one of them.

A password used elsewhere

When another site is breached, the passwords from it get tried against financial accounts. What helps: a password used only here, kept in a password manager.

A message that imitates us

An email or a message that looks like it came from us and points at a fake sign-in page. What helps: type our address yourself instead of following the link.

A device left signed in

A shared or unattended machine with the account still open on it. What helps: sign out when you leave a device that you don't control.

Someone offering to trade for you

An offer to trade the account on your behalf, or to recover your money for a fee paid up front. What helps: credentials belong to the account holder. We never need them, and neither does anyone legitimate.

What we do on our side

  • We send a confirmation link before an account can be used, so nobody can register against an address they don't control
  • We review every deposit and every withdrawal before the money moves. That's the last check if someone else has got in
  • Passwords are stored so they can't be read back. Nobody here can recover yours, and neither can you
  • Identity documents you send us are kept for that check and not used for anything else
  • Every funding request appears in the wallet, so you can see what has been raised on the account

Requests

What we'll never ask you for.

If a message asks for any of the things below, it isn't from us, however it's written.

Your password

Nobody here asks for your password, by email or by any other route. We don't need it to help with the account.

Card or bank details in a message

We don't ask for card or bank details in a message. If one does, it isn't from us.

Payment to release funds

There's no release fee, clearance charge or tax to pay before a withdrawal. Anyone asking for one is not us.

Remote access to a device

We don't ask you to install software, and we don't ask for remote access to your device.

How authentication works

You sign in with your email address and a password. Two-factor authentication is not offered, and there's no authenticator app or hardware key to add. That leaves the password as the whole lock, so a password you've used anywhere else should be treated as gone.

Account holder controls

What's in your hands.

Each of these answers one of the causes above. Together they cover what can be prevented.

1

A password used only here

Don't use this password anywhere else. If you've used it before, change it.

2

A password manager

A password manager lets you keep a long, different password for every site without memorising any of them.

3

Type the address yourself

Reach the site by typing our address instead of following a link in an email. That's how the imitation sign-in pages work.

4

Sign out when you leave

Sign out on any shared or unattended machine, and don't let the browser save the password on it.

5

The email account behind it

Password resets and account notices go to your registered email address. It needs protecting at least as well as the trading account.

6

Check the account record

Go through positions, funding history and account details. That's how you spot something unauthorised before anyone tells you.

If it happens

If you think someone else has access.

Four things, in order. The first two are yours to do, and they're the ones that matter most.

Change the password

Do it in Settings if you can still get in. If you can't, use the reset link on the sign-in screen.

Check positions and funding history

Look for any position, deposit or withdrawal you didn't open or ask for.

Tell us

Write to support@quantivofx.com and set out what you've found.

Secure the email account too

If someone may have got into your email as well, change that password too. It controls the reset for the trading account.

What not to do

  • Giving your password to anyone, including someone who says they work here
  • Paying a fee up front to anyone who offers to get your money back
  • Letting anyone else trade the account, whatever record they show you
  • Posting your balance, positions or account details in public

Enquiries

If a message looks wrong, ask us before you act on it.

Forward anything that claims to be from us and we'll tell you whether it is.