Account protection

Security controls and user responsibilities

Corvenhall Trust combines access controls, encryption, activity records and incident support. Effective protection also depends on secure user devices, careful verification and prompt reporting.

1. Multi-factor authentication

Multi-factor authentication adds a second verification step after the password. Supported methods may include an authenticator application, a device prompt or another method approved by the account provider. Users should enable the strongest available option during activation.

A second factor is highly recommended and may be required for sensitive actions. It does not make an account invulnerable: a fraudulent prompt can still be approved, and an email or mobile service can be compromised. Never disclose a code to a caller or enter one on a page reached from an unexpected message.

Recovery requires identity verification and may involve a temporary restriction. This delay protects the account when a device or factor is lost; support cannot bypass checks simply because a request is urgent.

2. Encryption and data protection

Information sent between a supported browser and the service is protected in transit using current transport encryption. Sensitive records are protected at rest within responsible systems using access controls and encryption appropriate to their function.

Encryption reduces exposure if traffic or stored media is intercepted, but it does not prevent every misuse. An authorised session, infected device or deceived user can still expose information after it has been decrypted for legitimate use.

Access to production and personal information should be limited by role, logged and reviewed. External providers handling data are assessed according to the service they perform and remain subject to contractual and legal requirements.

3. Fraud and phishing protection

Official web access uses the corvenhalltrust.net domain. Attackers can register a similar spelling, copy visual elements or pretend to be an employee. Verify the complete address, not just a logo or the first part of a sender name.

Official support does not request passwords, one-time codes, private keys, recovery phrases or remote control of a banking application. Messages should not create artificial urgency or instruct a transfer to an individual's account.

Where an agreed contact or anti-phishing reference is available, use it as one signal among several. Report suspicious communication to [email protected] using a new message rather than replying to the sender.

4. Login and activity alerts

Email or in-platform alerts can be issued when a new device signs in, credentials change or activity appears unusual. An alert is intended to prompt review; it does not prove that the activity was malicious or that every suspicious event will be detected.

Keep contact information current and protect the linked email account with its own unique password and multi-factor authentication. Check spam filtering if expected messages do not arrive.

If you do not recognise an event, change credentials from a trusted device, revoke active sessions and contact support. Do not use a link inside the suspicious alert until you have verified its origin.

5. Devices and sessions

The account area can show active or recently used sessions, including information such as device type, approximate location and time. Location is indicative because mobile networks, corporate connections and privacy tools can affect it.

Users should close sessions they no longer need and revoke any device they do not recognise. Automatic timeouts reduce the risk from an unattended browser, while high-risk actions may require renewed verification.

Shared or public computers should not be used for account access. Keep the operating system, browser and security software updated, and secure each device with a screen lock.

6. Account recovery

Recovery is deliberately more demanding than an ordinary login. Support may confirm identity, account history, contact channels and recent activity before restoring access. Additional documents can be required where information has changed or risk indicators are present.

During review, trading, connection or withdrawal functions may be restricted to prevent misuse. Support will explain the approved steps but will not ask for an existing password or security code.

Keep recovery information accurate before an emergency occurs. If the linked email or phone is compromised, report both the access problem and the compromised channel.

7. Connection permissions

External account connections can have read, trade or withdrawal permissions. Read access obtains information, trade access can place or manage eligible orders, and withdrawal access can move value from a venue. Permissions should match the minimum function required.

Corvenhall Trust does not require withdrawal permission for monitoring. Do not reuse connection secrets, display them in screenshots or transmit them through ordinary email. Use provider restrictions such as IP limits where available.

Review connections periodically and revoke unused or unexpected access from both Corvenhall Trust and the external provider. Regenerate a secret immediately if it may have been exposed.

8. Audit and activity history

Account records can include sign-ins, connection events and changes to settings or strategies. A time-ordered history supports personal review, customer support and investigation of disputed activity.

Logs are evidence, not an absolute account of human intent. Device sharing, compromised credentials and technical errors can affect what an entry means. Relevant records are retained in line with legal, security and operational needs.

Review history after an alert, setting change or unexpected result. Record the date and details before making further changes so support can investigate an intact sequence.

9. Incident support

For a suspected compromise, contact [email protected] and state that the matter is urgent. Include the approximate time, affected account and what you observed, but do not include a password, private key or one-time code.

Support can restrict access, revoke sessions, coordinate identity checks and escalate to security, compliance or an external provider. Updates are given through a verified channel, and restoration may wait until the immediate risk is understood.

Also secure the linked email, device and payment account. Where money has been sent fraudulently, contact the bank or payment provider immediately and make an appropriate report to Australian authorities.

Security controls reduce risk; they do not guarantee that an account, device, provider or market will never be affected by an incident.

Security checklist for Australian users

Before funding an account, confirm that multi-factor authentication is active, the recovery channel is current and no unknown session is listed. Bookmark the official site rather than relying on advertising or message links, and verify payment instructions in a separate authenticated session.

After any material account change, review the audit history and external venue permissions. If a device is lost, an email account is compromised or a transfer instruction changes unexpectedly, treat the event as a security incident and contact support and the relevant financial institution immediately.