Your account is only useful if it is yours alone. This page explains, in plain terms, the protections built into AvenQuant, the ones you switch on yourself and what we do when something goes wrong.
Nine layers of protection
No system is perfectly secure, and we do not claim ours is. What we do is combine several independent safeguards, so that a failure in one is caught by another. Some of them work automatically. Others depend on you turning them on, so we say clearly which is which.
1. Two-factor sign-in (2FA / MFA)
Two-factor sign-in asks for a second proof, on top of your password, each time you log in. We support time-based codes generated by an authenticator app on your phone. A stolen or guessed password is then not enough to enter your account.
We strongly recommend that you switch it on during your first call with your personal manager, and we require it before a withdrawal can be requested. If you lose your phone, you can recover access with the backup codes shown when you set it up, or by completing the identity check described in point 6.
2. Encryption
Data that travels between your device and our servers is protected with modern TLS encryption, so it cannot be read on the way. Data that we store, including your personal details, verification documents and exchange connection keys, is encrypted at rest.
Encryption keys are kept separately from the data they protect, and access to production systems is limited to the staff who need it for their work and is logged. Encryption is applied to the account area, the dashboard and the support systems.
We also test our own defences. Independent reviews of the platform are carried out from time to time, and issues they find are fixed on a priority basis.
3. Protection from fraud and phishing
Criminals copy websites and emails to trick people into handing over passwords. Our only official address is avenquant.org, and our emails come from @avenquant.org. Check both every time.
You can also set a personal security phrase in your account. Genuine messages from us include it, so an email without it is one to distrust. We never ask for your password, your 2FA codes or the secret part of an API key. Read the Fraud warning for examples.
4. Sign-in notifications
When your account is signed in from a device we have not seen before, we send an email so that you find out at once. We do the same for a password change, a change of email address and unusual activity such as many failed attempts in a short time.
If you receive a notification you do not recognise, change your password immediately, end all other sessions (see point 5) and contact us. The sooner we hear, the more we can do.
5. Devices and sessions
Your account shows every active session with the device type, the approximate location and the time of last use. You can end any of them from your settings with one click, which signs that device out immediately.
Sessions also end automatically after a period of inactivity, so a phone left unlocked on a train does not stay signed in indefinitely. On a shared or public computer, always sign out yourself when you finish.
6. Account recovery
If you cannot sign in, start with the password reset link. If that is not enough, for example because you no longer have your authenticator, contact support. We will ask you to prove your identity with the same kind of documents used at registration, and we may call you back on the number we already hold.
To protect you from someone who has taken over a phone or email account, withdrawals may be held for a short cooling-off period after a recovery. Support will tell you how long it is. We cannot bypass these checks, even for a client we know well.
7. API key permissions
When you connect an exchange, you create an API key on that exchange and give it to us. Keys can carry different permissions: reading balances, placing trades and withdrawing funds. We work with keys that can read and trade, and we tell you to keep withdrawal permission switched off.
With withdrawal off, even a leaked key cannot move your money out of the exchange. Where the exchange supports it, restrict the key to our published IP addresses, and delete the key on the exchange if you stop using the platform.
8. Audit history
The audit history in your account lists sign-ins, exchange connections, changes to strategies and changes to security settings, each with a date and time. Nothing on the list can be edited by you or by us.
Check it now and then. If an entry does not match something you did, treat it as a warning and follow the steps in point 9. The same history helps our support team understand exactly what happened when you ask for help.
9. Help when something goes wrong
If you suspect that someone else has access to your account, email [email protected] or call your personal manager straight away, and use the words "security incident" so that the message is triaged first. We can lock your account within minutes to stop any further activity, and we will pause your strategies if needed.
After that, our team investigates using the audit history, tells you what we found and what we recommend, and escalates to the compliance officer and, where the law requires it, to the relevant authority. You will hear from a named person, in writing, at each stage, and we will not ask you to guess what is going on. If you disagree with how we handled it, the complaints procedure applies.
Who does what
Security is shared. Some protections we run for you, and others only work if you use them.
Protection
What we do
What you do
Sign-in
Offer two-factor codes and lock accounts after repeated failed attempts
Switch on 2FA and keep the backup codes offline
Data
Encrypt data in transit and at rest and restrict staff access
Keep your devices updated and locked
Messages
Send email only from our domain and include your security phrase
Check the address and phrase, and report anything odd
Exchange keys
Store keys encrypted and use only the permissions granted
Grant reading and trading only, and delete unused keys
Monitoring
Log activity and alert you to unusual sign-ins
Act on alerts and review your audit history
Found a weakness? If you believe you have found a security vulnerability in our website or platform, please email [email protected] with the subject "Security report" and enough detail for us to reproduce it. Please do not access other people's data or disrupt the service while testing. We will acknowledge your report, keep you informed and fix genuine issues promptly.
What you can do today
Most account takeovers begin with a reused password or a convincing fake message, not with a break-in to a company. These five habits close most of those doors.
Use a password you use nowhere else, ideally from a password manager.
Switch on two-factor sign-in and store the backup codes offline.
Keep withdrawal permission off on every API key you create.
Type our address yourself instead of following links in messages.
Review your active sessions and audit history each month.
Security is not a guarantee of results. These measures protect access to your account and your data. They do not remove the market risk of trading, which is explained on the Risk disclosure page. Identity checks that run alongside them are described on the AML / KYC page.