Australian investor resource

Account and platform security

Security is shared between platform controls, service providers and careful user behaviour.

01

Multifactor authentication

LithVestor supports an additional authentication step for sensitive account access. Users should enable it at setup and keep recovery methods in a secure place separate from the main device.

Recovery requires identity checks and may temporarily restrict account actions. Support will never ask you to disclose a one-time authentication code.

For Multifactor authentication, Account and platform security uses a documented sequence rather than an unexplained outcome. The relevant account record, setting, provider response or market input should be reviewed in context, because an isolated alert can be incomplete or misleading. Australian users should compare what is shown with the published fees, risk controls and support process before acting.

On the security page, the practical consequence of Multifactor authentication depends on the user’s verified account, enabled services and current market conditions. LithVestor explains the available controls and keeps material steps visible, while the user retains responsibility for checking details, protecting access and deciding whether the potential loss is acceptable. No analytical output removes volatility, liquidity or third-party risk.

Practical check

Checkpoint 101 on security: review this topic against your own objectives, available capital and tolerance for loss. Keep a dated record of decisions and contact [email protected] if an account control or published condition is unclear.

02

Encryption

Connections use encrypted transport where supported, and stored information is protected according to its sensitivity and operational purpose. Access is limited to systems and personnel that need the data.

Encryption reduces exposure but does not replace strong credentials, secure devices or careful handling of exports and screenshots.

For Encryption, Account and platform security uses a documented sequence rather than an unexplained outcome. The relevant account record, setting, provider response or market input should be reviewed in context, because an isolated alert can be incomplete or misleading. Australian users should compare what is shown with the published fees, risk controls and support process before acting.

On the security page, the practical consequence of Encryption depends on the user’s verified account, enabled services and current market conditions. LithVestor explains the available controls and keeps material steps visible, while the user retains responsibility for checking details, protecting access and deciding whether the potential loss is acceptable. No analytical output removes volatility, liquidity or third-party risk.

Practical check

Checkpoint 102 on security: review this topic against your own objectives, available capital and tolerance for loss. Keep a dated record of decisions and contact [email protected] if an account control or published condition is unclear.

03

Fraud and phishing protection

Official communication uses the lithvestor-ai.com domain. Messages that demand immediate transfers, software installation or secret codes should be treated as suspicious.

Verify unusual contact through the published support address. A custom phrase or other verification control may be used where available, but users should still inspect the destination domain.

For Fraud and phishing protection, Account and platform security uses a documented sequence rather than an unexplained outcome. The relevant account record, setting, provider response or market input should be reviewed in context, because an isolated alert can be incomplete or misleading. Australian users should compare what is shown with the published fees, risk controls and support process before acting.

On the security page, the practical consequence of Fraud and phishing protection depends on the user’s verified account, enabled services and current market conditions. LithVestor explains the available controls and keeps material steps visible, while the user retains responsibility for checking details, protecting access and deciding whether the potential loss is acceptable. No analytical output removes volatility, liquidity or third-party risk.

Practical check

Checkpoint 103 on security: review this topic against your own objectives, available capital and tolerance for loss. Keep a dated record of decisions and contact [email protected] if an account control or published condition is unclear.

04

Login alerts

Email or in-product notices may be issued after a new-device login or activity that differs from the account pattern. An alert is a prompt to inspect activity, not proof that fraud occurred.

If you do not recognise an event, change the password from a trusted device and contact support promptly.

For Login alerts, Account and platform security uses a documented sequence rather than an unexplained outcome. The relevant account record, setting, provider response or market input should be reviewed in context, because an isolated alert can be incomplete or misleading. Australian users should compare what is shown with the published fees, risk controls and support process before acting.

On the security page, the practical consequence of Login alerts depends on the user’s verified account, enabled services and current market conditions. LithVestor explains the available controls and keeps material steps visible, while the user retains responsibility for checking details, protecting access and deciding whether the potential loss is acceptable. No analytical output removes volatility, liquidity or third-party risk.

Practical check

Checkpoint 104 on security: review this topic against your own objectives, available capital and tolerance for loss. Keep a dated record of decisions and contact [email protected] if an account control or published condition is unclear.

05

Devices and sessions

Active sessions can be reviewed and revoked. Sessions may end automatically after inactivity or after a security-sensitive account change.

Remove devices you no longer use and do not leave an unlocked session on a shared computer.

For Devices and sessions, Account and platform security uses a documented sequence rather than an unexplained outcome. The relevant account record, setting, provider response or market input should be reviewed in context, because an isolated alert can be incomplete or misleading. Australian users should compare what is shown with the published fees, risk controls and support process before acting.

On the security page, the practical consequence of Devices and sessions depends on the user’s verified account, enabled services and current market conditions. LithVestor explains the available controls and keeps material steps visible, while the user retains responsibility for checking details, protecting access and deciding whether the potential loss is acceptable. No analytical output removes volatility, liquidity or third-party risk.

Practical check

Checkpoint 105 on security: review this topic against your own objectives, available capital and tolerance for loss. Keep a dated record of decisions and contact [email protected] if an account control or published condition is unclear.

06

Account recovery

Recovery requires sufficient information to establish control of the account. Additional checks protect against an attacker using partial personal details to take over access.

During recovery, some functions may be restricted. Accurate, current profile information helps the team resolve the request safely.

For Account recovery, Account and platform security uses a documented sequence rather than an unexplained outcome. The relevant account record, setting, provider response or market input should be reviewed in context, because an isolated alert can be incomplete or misleading. Australian users should compare what is shown with the published fees, risk controls and support process before acting.

On the security page, the practical consequence of Account recovery depends on the user’s verified account, enabled services and current market conditions. LithVestor explains the available controls and keeps material steps visible, while the user retains responsibility for checking details, protecting access and deciding whether the potential loss is acceptable. No analytical output removes volatility, liquidity or third-party risk.

Practical check

Checkpoint 106 on security: review this topic against your own objectives, available capital and tolerance for loss. Keep a dated record of decisions and contact [email protected] if an account control or published condition is unclear.

07

API-key permissions

External connection keys should be limited to the smallest set of permissions needed. Read access, trade access and withdrawal access are materially different.

LithVestor does not require withdrawal permission for analytical monitoring. Rotate or revoke a key if it has been exposed or is no longer used.

For API-key permissions, Account and platform security uses a documented sequence rather than an unexplained outcome. The relevant account record, setting, provider response or market input should be reviewed in context, because an isolated alert can be incomplete or misleading. Australian users should compare what is shown with the published fees, risk controls and support process before acting.

On the security page, the practical consequence of API-key permissions depends on the user’s verified account, enabled services and current market conditions. LithVestor explains the available controls and keeps material steps visible, while the user retains responsibility for checking details, protecting access and deciding whether the potential loss is acceptable. No analytical output removes volatility, liquidity or third-party risk.

Practical check

Checkpoint 107 on security: review this topic against your own objectives, available capital and tolerance for loss. Keep a dated record of decisions and contact [email protected] if an account control or published condition is unclear.

08

Audit history

Account records may include logins, connections, strategy changes and material settings updates. These records help a user reconstruct what changed and support an incident review.

Inspect the history periodically and preserve relevant timestamps if reporting unexpected activity.

For Audit history, Account and platform security uses a documented sequence rather than an unexplained outcome. The relevant account record, setting, provider response or market input should be reviewed in context, because an isolated alert can be incomplete or misleading. Australian users should compare what is shown with the published fees, risk controls and support process before acting.

On the security page, the practical consequence of Audit history depends on the user’s verified account, enabled services and current market conditions. LithVestor explains the available controls and keeps material steps visible, while the user retains responsibility for checking details, protecting access and deciding whether the potential loss is acceptable. No analytical output removes volatility, liquidity or third-party risk.

Practical check

Checkpoint 108 on security: review this topic against your own objectives, available capital and tolerance for loss. Keep a dated record of decisions and contact [email protected] if an account control or published condition is unclear.

09

Incident support

Send urgent security concerns to [email protected] with a concise description and safe contact details. Do not attach passwords, one-time codes or full payment credentials.

The response may include session revocation, temporary restrictions, identity verification and escalation to the appropriate service provider. Updates are provided as reliable information becomes available.

For Incident support, Account and platform security uses a documented sequence rather than an unexplained outcome. The relevant account record, setting, provider response or market input should be reviewed in context, because an isolated alert can be incomplete or misleading. Australian users should compare what is shown with the published fees, risk controls and support process before acting.

On the security page, the practical consequence of Incident support depends on the user’s verified account, enabled services and current market conditions. LithVestor explains the available controls and keeps material steps visible, while the user retains responsibility for checking details, protecting access and deciding whether the potential loss is acceptable. No analytical output removes volatility, liquidity or third-party risk.

Practical check

Checkpoint 109 on security: review this topic against your own objectives, available capital and tolerance for loss. Keep a dated record of decisions and contact [email protected] if an account control or published condition is unclear.