Skip to content

Security

Your security is engineered in, not bolted on.

Layered protections across identity, money movement, data and operations — and clear steps you can take to protect yourself.

How we protect you

Controls at every layer.

Two-factor authentication

Authenticator-app codes with replay protection, trusted devices and one-time recovery codes.

Session control

See every active session and sign out any device instantly. Password changes revoke other sessions.

Step-up verification

Withdrawals require a fresh verification code, even when you're already signed in.

Risk monitoring

Unusual sign-ins, repeated failures and withdrawal velocity trigger automated holds and review.

Encryption

TLS everywhere; tax IDs and MFA secrets encrypted at rest with AES-256-GCM.

Server-side authority

Balances, prices, fees and order status are computed on our servers — never trusted from a browser.

Immutable ledger

Transactions and executions cannot be edited or deleted; corrections are separate, audited entries.

Audited staff access

Every sensitive action by Zenvex Capital staff requires a reason and is written to an append-only audit log.

What you can do

Five habits that stop most account takeovers.

  • Turn on two-factor authentication in Settings → Security.
  • Use a unique password of at least 12 characters, ideally from a password manager.
  • Review active sessions and trusted devices periodically.
  • Never share verification codes — Zenvex Capital staff will never ask for them.
  • Keep your email account secure; it is the recovery path for your investments.