Account and platform security

Nine controls that protect your access, your data and your trades, and what you can do to strengthen them.

Security on a trading platform depends on two parties: what Aurora Capital does with its infrastructure and what you do with your account. This page describes both, in the same order in which the controls appear inside the dashboard, so you can check each one and switch on those that are optional. The controls summarised on the home page come from this list.

1. Two-factor authentication (2FA)

You can protect your account with a one-time code generated by an authenticator app such as Google Authenticator or Microsoft Authenticator. We also accept FIDO2-compatible security keys. Two-factor is optional for signing in, but required to request withdrawals and to change your email or password.

If you lose your device, use the backup codes shown when you activate 2FA. If you do not have them either, follow the recovery process in point 6, which includes identity verification.

We recommend turning on 2FA on day one, even before connecting an exchange. It takes under two minutes and is the most effective barrier against stolen passwords, the most common cause of unauthorised access.

2. Data encryption

All communication between your device and Aurora Capital travels encrypted with TLS. Sensitive data at rest, such as verification documents, phone numbers and API keys, is stored encrypted on servers with restricted access.

Encryption applies to the web platform, the dashboard and the support systems. Only authorised staff, with access logging, can see client information, and only what they need to handle your case.

Encryption keys are managed separately from the data they protect and are rotated regularly. We also keep encrypted backups so that service can be restored after an incident without exposing user information.

3. Fraud and phishing protection

Our only official domain is auroracapital-ai.co. Any other site that uses our name or logo does not belong to us. Official emails come from addresses on that domain and will never ask for your password, your 2FA code or your full API key.

You can set a protection code in your profile: we include it in the emails we send you, so if a message does not carry it you will know it is not ours. More detail in the fraud warning.

Official addresses are listed on the contact page, and any change of channel is announced there first, so you can always compare what you receive with what we have published.

If you get a message that claims to be ours and pushes you with urgency, be suspicious. There is no case in which you must pay to recover your account or unlock a withdrawal. When in doubt, write to the address on this page.

4. Login notifications

Each time someone signs in to your account from a device or place we have not seen before, you receive an email with the date, approximate time, browser and estimated city. If it was not you, the same message includes a button to close every session.

We also warn you about suspicious activity, such as several failed attempts in a row or setting changes outside the usual pattern.

Alerts go to your registered email and you can choose which kinds you want. We suggest keeping all of those related to sign-in, security changes and withdrawals, because they are the ones that help you spot a problem in time.

5. Device and session management

In the security section of the dashboard you see the active devices and sessions with their last use. You can close any of them remotely with one click, and the access is revoked immediately.

Idle sessions close automatically after a set time, and sessions from shared computers close when the browser closes.

If you change phone or computer, we advise you to close the old device's session from the dashboard. You can also mark a device as trusted for a limited period, so you do not repeat the code at every sign-in from your usual equipment.

6. Account recovery

If you forget your password, you can reset it with a link sent to your email. If you lost access to your email or to the second factor, our team will ask you to verify your identity with a document and a live photo before resetting anything.

For safety, temporary restrictions apply after a recovery: withdrawals are held for a short period and you receive notices on every registered channel.

During the entire process we will never ask for your password or your 2FA code. Only the verified holder can complete the recovery, and if the document data does not match the registration the process stops and is escalated to the compliance team.

7. API key permissions

API keys let Aurora Capital trade on your exchange. They can carry read permission, trade permission or withdrawal permission. We recommend, and only accept, keys with read and trade; a key with withdrawal permission is rejected by our system.

You can always revoke the key from the exchange, and that disconnects the platform instantly. If the exchange allows it, limit the key to our IP addresses.

Our connection test checks the permissions each time you add a key, and the dashboard warns you if a key is later changed on the exchange side to include permissions we do not accept.

If you need to change permissions, create a new key rather than editing the old one, and delete the old one. That way your history shows when the change happened and you keep a tidier view of the keys in force.

8. Audit history

The dashboard keeps a record of what happens in your account: sign-ins, exchange connections and disconnections, strategy changes, parameter edits and withdrawal requests. Each entry carries date, time and device.

Check it now and then; if you see something you do not recognise, you can report it straight from the entry and our team opens the case with priority.

The history is kept for the period set in the privacy policy and can be exported on request if you need it for a claim or your own review. Records cannot be edited by the user, which makes them reliable as evidence.

9. Incident support

If you suspect that someone accessed your account, write to [email protected] or call your account manager, who is available 24 hours a day. We can lock the account at once, close every session and suspend withdrawals while the matter is investigated.

The case is escalated to the security team and we update you by email on each step: what we found, what measures we took and what you need to do. Where it applies, we guide you on reporting to the authorities.

Where appropriate we also share what we learned, in general terms, so that other users can protect themselves against the same technique.

The more information you give us when reporting, the faster we can act: date and time of the event, device, suspicious emails or messages and screenshots. Meanwhile, change your email password and revoke API keys from your exchange.