Security

Nine measures protect a Nuvaultance account, and each one is written out here the way it actually works. No security layer removes market risk, but every layer removes a way for someone else to reach your account.

The nine measures in detail

1. Two-factor authentication

Every account supports two-factor authentication through an authenticator app, and it is mandatory before the first withdrawal. Recovery follows a verified identity check with support, never a code sent by email. Without the second factor, a stolen password alone cannot open an account.

2. Encryption

Data is encrypted in transit with TLS and at rest in storage, with identity documents held in a separate store from general account data. Access to decrypted document data is limited to the compliance function and logged. Keys are managed by the platform team under a documented rotation schedule.

3. Fraud and phishing protection

Nuvaultance communicates from one domain, nuvaultance-ai.com, and from the support address [email protected]. We never ask for your password, your 2FA codes, or remote access to your device. If a message pressures you to act immediately, treat it as suspicious and check the fraud warning page.

4. Login alerts

Every sign-in from a new device or location triggers an email alert with the device type, approximate location, and time. Alerts about activity you do not recognize include a one-tap path to secure the account. Suspicious patterns, such as rapid attempts from different regions, freeze the login until you confirm it.

5. Device and session management

The account settings list every active session with its device and last-seen time, and any session can be signed out remotely. Sessions expire automatically after a period of inactivity, and password changes invalidate all other sessions. Shared or public computers should never use the stay-signed-in option.

6. Account recovery

Recovery starts with identity verification against the documents collected at onboarding, followed by a cooling-off period before sensitive changes take effect. Support will never rush you through recovery or ask for codes. Lost-phone situations are handled by re-enrolling 2FA after verification, which temporarily limits withdrawals for your protection.

7. API key permissions

Exchange connections created for strategy execution are read-and-trade keys. Withdrawal permissions are never enabled on API keys, and keys are stored encrypted with per-connection scoping. You can review which connections exist and revoke any of them from the account settings at any time.

8. Audit log

Logins, exchange connections, strategy changes, and setting updates are recorded in an audit log visible in your account. Each entry shows what changed, when, and from which device. If anything ever looks wrong, that log is the fastest way to establish the timeline, and support reviews it with you.

9. Incident support

If you suspect unauthorized access, write to [email protected] and the account can be frozen while the facts are established. Incidents are escalated to a named handler, communicated on a stated schedule, and closed with a written summary. Security events never result in a request for your credentials.

What security actually changes

Three situations clients ask about most often.

An unknown sign-in appears

End the session from device management, change the password, and check recent activity in the audit log. If anything is unclear, freeze first and ask questions second by contacting support.

Someone asks for a code

Hang up or stop replying. Nuvaultance staff never ask for 2FA codes, passwords, or remote access, whatever the stated reason. Report the contact so other clients can be warned.

Your phone is lost

Sign out of all sessions from a desktop if available, then contact support to re-verify and re-enroll 2FA. Withdrawals stay limited until re-enrollment completes, which is deliberate.

Identity verification and asset protection

Security at Nuvaultance is maintained, not merely installed: settings are reviewed against current threats, incidents anywhere in the industry are studied for lessons, and the measures below are the ones that have actually mattered.

Identity verification at onboarding protects your account and is required by Canadian anti-money-laundering rules; the details are in the AML/KYC policy. Verification is also what makes recovery possible when a device is lost, and what prevents a stranger from redirecting your withdrawals.

Deposits and coverage in Canada. Cash deposits with a member institution may be eligible for CDIC coverage, subject to its rules. Eligible securities held by a member investment dealer may be covered by CIPF, subject to its limits. Crypto and other digital assets are generally not covered by CDIC or CIPF.

It is worth reading that twice, because clients often assume protection is uniform. Cash held with a member institution and securities held by a member investment dealer sit inside schemes with defined limits and conditions. Digital assets generally sit outside them, which is why the custody arrangements for that sleeve are documented separately and stated in writing on request.

How the layers stack

Think of the nine measures as three rings. The first ring stops attackers at the door: 2FA, encryption, and scoped API keys mean stolen credentials alone accomplish nothing. The second ring tells you when something is wrong: login alerts, session management, and the audit log surface activity while it is happening, not in a quarterly review. The third ring limits the damage of whatever gets through: recovery verification, incident support, and withdrawal controls that require your identity and a destination in your own name.

No ring is optional, and no ring is decorative. A platform that has 2FA but no session management protects the front door and leaves the windows open; one with alerts but unscoped API keys watches attentively while the keys walk out. Security reviews at Nuvaultance check all three rings together, because attackers do not attack in the order that is convenient to defend.

Your part of protection

Use a unique password stored in a password manager, keep 2FA enabled, and read the alerts the platform sends. Treat any unexpected call, email, or message about your account as suspicious until you have verified it through the official domain. Security works as a partnership: the platform locks the doors, and you decide who gets a key.

Three habits close most of the remaining gaps. Type the domain yourself instead of following links in messages about your account, so a lookalike address never receives your password. Keep the recovery email and phone number current, because recovery paths rot quietly until the day they are needed. And when a notification looks odd, act within minutes rather than days; the difference between an alert and a loss is usually reaction time.

If you notice anything that seems wrong and are unsure whether it matters, report it anyway. A false alarm costs support five minutes; a real one caught late costs far more. Reports go to [email protected] and are answered by people, with the option to freeze the account first and ask questions second.