Security

Nine controls around your account

Security at Renevex is engineered into the product, not bolted on at the end. This page walks through the nine controls that protect your account, your data and your funds, and the part you play in each of them. If anything is still unclear after reading, support answers security questions first in the queue.

2FA / MFA

Second factor by authenticator app, with a verified recovery path.

Encryption

Protected in transit and at rest, keys rotated on schedule.

Anti-fraud

Official domains and a verification code in every message.

1. Two-factor authentication (2FA / MFA)

We recommend switching on a second factor on day one: on top of your password, the account asks for a code from an authenticator app, refreshed every thirty seconds and working without mobile reception. With 2FA active, a leaked password on its own cannot open your account, and that single change defeats the overwhelming majority of account-takeover attempts in circulation.

If you lose the device with the authenticator, recovery deliberately requires identity verification with a document. That friction exists so nobody can replace your second factor by pretending to be you. Once identity is confirmed, the team clears the old factor and you register the new device in minutes. Keep the backup codes printed or in a password vault:

On authenticator choice: any reputable app works, from Google Authenticator to Aegis, and more than one device can be registered as backup. What we do not recommend is SMS as the only factor, given its known weakness to SIM-swap attacks; if it is genuinely the only option, enable it anyway, because a weak factor still beats none at all.

they solve most emergencies without waiting.

2. Encryption of data

Everything travelling between your browser and the platform is encrypted with TLS, so intercepted traffic cannot be read. Sensitive information at rest, identity records and account details, stays encrypted in storage, with read access restricted by role.

The scheme covers the authentication, identity-verification and trade-logging systems, keys are rotated on a defined cycle, and internal traffic between platform systems rides the same

Key custodianship deserves a plain statement: encryption keys are held centrally, rotated on a published schedule and never exported to staff laptops or personal storage. Access to the key store itself requires dual authorisation, so a single compromised credential cannot expose the stored data even from the inside.

protections so no internal hop becomes the weak link in the chain.

3. Fraud and phishing protection

Renevex sends official communications only from its own domains. A look-alike domain with one letter changed is the classic signature of a scam. Every transactional email carries a personal verification code that you compare with the one stored in your account: if the codes differ, the message did not come from us.

We never ask for your full password, a 2FA code or complete card details by phone or email. If you receive such a request in our name, do not reply and forward it to [email protected]. Every report is analysed and feeds the takedown of imitator domains. Three quick checks unmask nearly every fake: sender on the official domain, verification code

Reporting pays forward: the domains you report get taken down, and the pattern you flag is added to the detection list that protects every other account. Most imitator domains in our takedown log began as a single client forward, which makes the two minutes you spend reporting worth considerably more than they appear.

matching your account, and no request for secrets. Fail one, and the message is a scam.

4. Login notifications

Every sign-in from a new device triggers an email with the date, time and approximate location. We also flag unusual behaviour, such as repeated failed password attempts or access from a country that has never appeared in your history.

Received an alert for a login that was not yours? Change the password immediately, end the open sessions in your settings and confirm 2FA is active. If the location in the alert is

A quick word on where alerts land: they go to the registered email, which is why that inbox deserves its own strong password and 2FA where the provider offers it. The alert system is only as good as the mailbox that receives it, and a neglected inbox quietly delays exactly the warnings you most want to see quickly.

impossible, change your registered email password too: it is the master key to account recovery.

5. Device and session management

The security panel lists every live session with its device, operating system and last activity. You can end any single session or all of them at once, revoking access without changing your password.

Sessions expire automatically after a period of inactivity, and saved logins are invalidated whenever the password changes or the second factor is reset. On a shared computer, leave "remember this device" unchecked and always sign out when you finish.

6. Account recovery

Password resets use a single-use link that expires quickly and works exactly once. More sensitive changes, such as replacing the registered email or losing the second factor, go through document-based identity verification before anything moves.

During recovery, withdrawals are temporarily held: that window stops an attacker emptying the account while the rightful owner is regaining control. The hold lifts as soon as verification completes.

7. API key permissions

Keys connecting the platform to exchanges are created with the smallest workable scope: reading data and placing orders. Withdrawal, the third possible permission, stays disabled and is never required for the platform to operate.

Every key accepts an IP restriction and can be revoked on the spot. Give keys descriptive names ("renevex engine"), test them, note the date and revoke anything unused past ninety days; the panel shows each key's age so the review takes seconds.

8. Audit history

Your account keeps a complete record: logins, integration connections, strategy changes and configuration edits, each line timestamped. It is the source for reconstructing anything that looks out of place.

The same trail is retained on the infrastructure side for incident investigation and compliance obligations. Spot a movement in the history you do not recognise? Contact support immediately: we freeze account activity and open a review.

9. Incident support

Suspect unauthorised access or odd activity? Write to [email protected] with the subject "incident". You can request a preventive freeze of the account while we investigate, and that is exactly what we recommend whenever the doubt is serious.

Incident communication follows a fixed order: confirmation of receipt, the immediate measures applied and, when the investigation closes, a summary of the cause and the fix. When you report, include the time you noticed, the device and network you were on, and any suspicious message received beforehand; each of those shortens the investigation and helps protect neighbouring accounts.