Security at Aurora Finspire

Your account holds personal details and access to your trading activity, so we protect it in layers. Nine measures are described below, each with what it does, whether you must use it and what to do if something goes wrong. None of them removes market risk, but together they make it much harder for anyone else to get at your account.

  • Applies to every account
  • Support reachable around the clock for account incidents

The nine protections

1. Two-factor authentication

Sign-in can be protected with a time-based code from an authenticator app, or with a code sent to your mobile. The authenticator app is the stronger choice because codes are generated on your own device and cannot be intercepted in a text message.

Two-factor sign-in is mandatory for withdrawals and strongly recommended for every login. If you lose your device, recovery goes through the identity check described in point 6, never through a single email link.

2. Encryption

Data is encrypted in transit using modern TLS, so anything you type or receive between your browser and our servers cannot be read on the way. Stored personal data and API credentials are encrypted at rest.

Encryption keys are held apart from the databases they protect, and only a small number of named engineers can reach the systems that manage them. Access is logged and reviewed.

3. Fraud and phishing protection

Our only official domain is aurora-finspire.com. Messages claiming to come from us that link anywhere else should be treated as suspect. You can set a personal anti-phishing code in your settings, and every genuine email from us will display it.

We will never ask for your password, your authenticator codes or your API secret. See the Fraud warning for how impersonators work.

4. Login notifications

We email you, and can send a push notification, when your account is opened from a new device or location, when a password or two-factor setting changes and when we notice unusual behaviour such as many failed attempts.

If an alert is not about something you did, change your password immediately and contact support. The alert contains a direct link to end all sessions.

5. Devices and sessions

Your settings list every active session with the device type, approximate location and last activity. You can end any session individually or all at once.

Idle sessions end automatically after a period of inactivity, and a session that has been open for a long time asks you to confirm your identity again before sensitive actions.

6. Account recovery

Recovering an account means proving that you are its owner. We ask for a photo of your ID, a short live check and confirmation of details held on file, then review the case manually.

Recovery is deliberately slower than a normal login, and funds cannot be withdrawn for a cooling-off period afterwards. This protects you if someone else is trying to take over your account.

7. API key permissions

When you connect an exchange you create a key there, and you choose its rights: read-only, trade or withdraw. The platform needs read and trade rights only, and connections that include withdrawal rights are rejected.

You can also limit a key to our server addresses, and revoke it at the exchange at any moment, which cuts our access instantly.

8. Audit history

Every login, connection, change of strategy and change of settings is recorded with a time stamp and shown in your activity log. The log cannot be edited by you or by us.

Checking it takes a minute and is the quickest way to spot something you did not do. Support can read it too, with your permission, when helping with a problem.

9. Incident support

If you think your account has been accessed without permission, ring your personal manager or write to [email protected]. We can lock the account within minutes and pause trading while we investigate.

You will hear from a named person, who explains what we found, what we did and what you need to do next. Serious incidents are escalated to our compliance lead the same day.

A shield with a padlock in front of a clock tower and a rising chart, in blue, red and white

Habits that keep you safer

  • Use a long, unique password kept in a password manager, never reused from another site.
  • Turn on authenticator-app sign-in on the day you register.
  • Type the address into your browser or use your own bookmark instead of clicking links in messages.
  • Keep your phone and computer updated, and avoid public wi-fi for anything involving money.

What security cannot do

Protecting an account is not the same as protecting its value. A strong lock cannot stop prices falling, and cryptoassets are not covered by the Financial Services Compensation Scheme. Cryptoassets are not covered by the Financial Services Compensation Scheme (FSCS). Sterling held in a bank account with a UK-authorised bank may be protected by the FSCS up to the applicable limit, but that protection does not extend to the value of cryptoassets or to losses caused by market movements.

For the risks that remain, read the Risk disclosure.

Security in everyday terms

What the nine measures look like when you actually use the platform.

Signing in on a new phone

You enter your password, then the six-digit code from your authenticator app. We email you to say a new device has signed in, with a link to end the session if it was not you. Withdrawals from that device stay blocked for a short period, which gives you time to react if your login has been copied.

Connecting an exchange

You create the key at the exchange and decide its rights. When you paste it into the dashboard the platform checks what it can do. If it finds withdrawal rights it refuses the connection and tells you why. The key is then stored encrypted, and its use shows up in your audit log.

Spotting a fake message

A genuine email from us shows your anti-phishing code, comes from our own domain and never asks you to log in through a link to confirm a payment. If the code is missing, treat the message as suspect and forward it to [email protected].

At a glance
MeasureYour choice?
Two-factor sign-inRequired for withdrawals, advised for login
EncryptionAlways on
Anti-phishing codeYou set it
Login alertsEmail on by default, push optional
Session timeoutAutomatic
API key rightsYou choose, withdrawal always refused
Audit logAlways on, read-only

How we protect the platform itself

Account-level controls only matter if the systems underneath are sound. Our servers sit behind firewalls that block everything except the traffic they need. Software is updated on a regular cycle, and security patches are applied as a priority. New code is reviewed by a second engineer before release, and sensitive changes are checked against a list of common weaknesses.

Staff access follows the principle of least privilege: people see only the data their job requires, every access to client records is logged and the logs are reviewed. Employees complete security training when they join and again each year, with extra practice in spotting phishing.

Testing and preparation

We carry out regular vulnerability scans and commission independent penetration testing, and any serious finding is fixed before it is closed. We also practise incident response, so that if something does go wrong the right people know what to do and in what order. Backups are encrypted and restored in test conditions to make sure they actually work.

If you believe you have found a weakness, please tell us through [email protected]. We take reports seriously, and we ask only that you give us reasonable time to fix a problem before discussing it publicly.