Security

Nine layers of protection for your account and data

Security is not one feature but a set of habits and controls that complement each other. Here is what we provide, and what you need to do on your side.

1. Two-factor authentication (2FA / MFA)

Besides your password, your account can be protected by a one-time code. The supported methods are an authenticator app on your phone (a code that changes every 30 seconds) and a code sent to your registered email. The authenticator app is stronger because its codes do not pass over the mobile network.

We strongly recommend enabling 2FA on every account, and it is required before you request your first withdrawal. If you lose your phone, recovery is done through identity verification by the support team, as described in point 6.

Back up the recovery codes shown when 2FA is enabled and keep them somewhere safe and separate from your phone, for example printed or handwritten. Without those codes, restoring access takes longer because it has to go through manual verification.

2. Data encryption

Data travelling between your device and our servers is protected by an encrypted connection (HTTPS with a modern TLS version). Stored data, such as profile information and API keys, is encrypted on the server side, while passwords are stored as hashes and cannot be read by our staff.

Encryption applies across all systems that store or process user data, and access to those systems is limited to staff who need it for their work, with every access logged.

Encryption keys are managed separately from the data they protect and are rotated regularly. Backups are encrypted as well, so a stored copy cannot be read without the matching key.

3. Protection from fraud and phishing

Make sure you open the site only through the official domain neovalor-ai.com. Our official messages are sent only from addresses on the same domain, and our team never asks for your password, 2FA code or API key.

You can set a personal anti-phishing code. It appears in every official email from us, so an email without it can be ignored. If you receive a suspicious message, forward it to [email protected] and read the fraud warning.

Also watch for the common signs of phishing: an urgent tone, threats to block your account, links with a slightly different domain spelling, or a request to install a remote-control app. The only safe way is to type the official address directly into the browser or use a bookmark you saved yourself.

4. Login notifications

Every login from a new device or location triggers a notification by email, and by in-app notification if enabled. The notice includes the time, the type of device and the approximate location so you can tell whether it was really you.

Activity that looks suspicious, for example many failed login attempts or a sudden change to security settings, produces additional alerts. If it was not you, change your password immediately and contact support.

You can choose which kinds of notification to receive, but notices about new-device logins and security changes cannot be switched off because they concern the safety of the account.

5. Device and session management

On the dashboard you can see all active sessions with their devices. Each session can be revoked one by one, or all at once, and access from a revoked device stops immediately.

Sessions that are not in use end automatically after a while so the account does not stay open on a shared computer. A good habit: always log out when you are done if you use a device that is not yours.

If you revoke a session you do not recognise, also change your password and check the list of connected API keys. A revoked session cannot be restored, and that device must log in again with a 2FA code.

6. Account recovery

If you forget your password, a reset link is sent to your registered email. If you lose access to your 2FA device, recovery requires an identity check, which means matching account data against an identity document and, where needed, a selfie.

This process is deliberately not instant. While recovery is under way, withdrawals can be held temporarily to stop others from taking advantage of your account. We will not approve a recovery based only on a request over chat or phone without verification.

Once the account is restored, we advise you to change your password, recreate your API keys and review the audit history to see whether anything happened while the account was not in your control.

7. API key permissions

When you connect an exchange, you set the API key permissions yourself. There are three common levels: reading data, trading, and withdrawing funds. Neo Valor only needs read and trade permissions for strategies to run.

The withdrawal permission should never be enabled. That way, if the key leaks, whoever holds it cannot move funds out of your exchange. You can also restrict the key to specific IP addresses if your exchange offers it.

If you change devices or want to stop using Neo Valor, revoke the key directly in the exchange settings. Revocation at the exchange takes effect immediately, without waiting for any action from us.

8. Audit history

Every important event on the account is recorded: logins, new exchange connections, strategy changes and changes to security settings. This history is available to you on the dashboard, with the time and the device used.

The audit history makes it easier to trace what happened if a result surprises you. These records are also the basis for the support team when investigating a problem report, and they are kept in line with the Privacy Policy.

9. Help during an incident

If you suspect your account has been compromised, email [email protected] or contact your personal manager. We can freeze the account temporarily to stop unauthorised activity, then review the audit history together with you.

Reports involving potential loss are handled with priority and escalated to the security team. You will receive updates on the status of the handling, and the findings are explained in clear language. For complaints that remain unresolved, see the complaints procedure.

Security checklist for you

Eight simple habits that prevent most account compromises:

  • Enable 2FA with an authenticator app, not just email.
  • Use a long password that you have never used on another service.
  • Keep recovery codes somewhere safe and separate from your phone.
  • Set the anti-phishing code and check it appears in every email.
  • Create a dedicated API key without withdrawal permission, and restrict IP addresses where possible.
  • Review the active session list and audit history at least once a week.
  • Never log in through a link from a chat message or an email you did not ask for.
  • Keep your operating system and browser updated, and avoid public Wi-Fi for logging in.
Division of security responsibilities
AreaWhat we doWhat you do
Account accessProvide 2FA and session controlEnable 2FA, protect your password
DataEncrypt in transit and at restKeep your devices secure and up to date
API keysStore encrypted, ask only for needed permissionsLimit permissions, revoke when unused
FraudSend official messages with a protective codeCheck the domain and report suspicious messages

Security is a shared responsibility. Our systems protect the platform side, but a weak password, an insecure device or a shared API key can open a gap on your side. Also read about cybersecurity risks and the identity verification policy.