Security
Your security is engineered in, not bolted on.
Layered protections across identity, money movement, data and operations — and clear steps you can take to protect yourself.
How we protect you
Controls at every layer.
Two-factor authentication
Authenticator-app codes with replay protection, trusted devices and one-time recovery codes.
Session control
See every active session and sign out any device instantly. Password changes revoke other sessions.
Step-up verification
Withdrawals require a fresh verification code, even when you're already signed in.
Risk monitoring
Unusual sign-ins, repeated failures and withdrawal velocity trigger automated holds and review.
Encryption
TLS everywhere; tax IDs and MFA secrets encrypted at rest with AES-256-GCM.
Server-side authority
Balances, prices, fees and order status are computed on our servers — never trusted from a browser.
Immutable ledger
Transactions and executions cannot be edited or deleted; corrections are separate, audited entries.
Audited staff access
Every sensitive action by Zenvex Capital staff requires a reason and is written to an append-only audit log.
What you can do
Five habits that stop most account takeovers.
- Turn on two-factor authentication in Settings → Security.
- Use a unique password of at least 12 characters, ideally from a password manager.
- Review active sessions and trusted devices periodically.
- Never share verification codes — Zenvex Capital staff will never ask for them.
- Keep your email account secure; it is the recovery path for your investments.