Account and platform security: nine layers of protection

LiraX protects your account and data with nine measures that complement each other. Below we explain in plain language what each measure does, what it expects from you, and where its limits are.

  • Two-factor authentication
  • Encryption
  • Audit history

Two-factor authentication (2FA/MFA)

To make it harder to get into your account even if your password is stolen, we offer a second verification step. The supported methods are a one-time code from an authenticator app on your phone, a code sent by SMS, and a code sent by email. An authenticator app is considered safer than SMS, so we recommend it first.

At login, 2FA is optional but strongly recommended. For sensitive actions such as submitting a withdrawal, creating an API key and changing security settings, the second verification is mandatory. If you lose your device, you can regain access during recovery with the backup codes you saved earlier, or through identity verification with the support team.

To set it up, go to Security and then Two-factor authentication in the dashboard, scan the QR code with your app and store the backup codes somewhere offline. Each backup code can be used only once.

Encryption

All communication between your browser and the platform is encrypted with current TLS versions, which stops your data from being read on the network. Sensitive data at rest is protected with strong symmetric encryption. Your password is stored as a one-way hash, so nobody, including our team, can see it.

The secret part of any API key you connect is stored encrypted and is not shown again after saving. Only the systems that need it for their work, such as authentication, payments and strategy services, can reach encrypted data; access is logged and reviewed regularly.

Fraud and phishing protection

Our official web address is the lirax-app.org domain, and official emails come only from that domain. If even one letter of the address differs, or you arrived through a shortened link, do not log in. For look-alike fake sites see the Fraud warning page.

In your account settings you can choose your own protection code; it appears inside the emails we send you and helps you confirm the message really comes from us. Our staff never ask for your password, verification code or API secret; if you receive such a request, do not reply and let us know.

Login alerts

When someone logs in from a new device or an unusual location, you receive an email or push notification. Alerts are also sent for events such as a password change, API key creation, a change to security settings and a withdrawal request. You can switch alerts on and off in account settings; at the least, keep login and withdrawal alerts on.

When the system detects suspicious activity, for example login attempts from different countries in a short time or repeated failed passwords, it asks for extra verification and, if needed, temporarily restricts the session. If you receive an alert you do not recognise, change your password straight away and write to the support team.

Check who an alert comes from: genuine alerts come from our official domain, carry the protection code you chose, and never send you to a link to type in your password.

Device and session management

In the security area of the dashboard you can see all open sessions with the device type, approximate location and time of last activity. You can end a session you do not recognise with one click, or sign out of all devices; access is revoked immediately.

Sessions that stay idle for a set time are closed automatically. If you logged in on a shared or public computer, remember to sign out when you finish. We recommend logging in only from your own devices and keeping your screen lock and operating system up to date.

Avoid trading on public Wi-Fi; if you must, use a trusted mobile connection. When you spot suspicious activity, first close all sessions and then change your password.

Account recovery

If you lose your password or verification device, first try a password reset through the secure link sent to your email. If that is not enough, contact the support team; they may ask for identity documents and extra questions to confirm you are the account holder.

For your safety, recovery comes with some restrictions: account access is not opened until verification is complete, and after recovery withdrawals may be limited for a short time. This pause is there to stop someone who has taken over an account from moving funds out immediately.

API key permissions

The API key you create when connecting your exchange account has three separate permissions: read, trade and withdraw. LiraX asks for read and trade permission to work; it does not require withdraw permission. Keeping withdraw permission off means funds cannot be moved out even if the key is compromised.

Where possible, restrict the key at the exchange to the platform's IP addresses only (an IP allow list). Do not share the key, renew it at regular intervals, and delete connections you no longer use. In a suspicious situation you can revoke the key at the exchange immediately.

When a key is revoked the connection to the platform is cut; your open positions are not affected but no new trades are opened. You can create a new key and reconnect.

Audit history

Important events in your account are recorded with a timestamp, device and approximate location. The log includes logins, logouts, exchange connections, strategy starts and stops, and settings changes. That way you can always trace when something changed in your account.

If you see an unexpected change you can share the relevant record with the support team; during a review these records speed up our work. Audit records are kept in line with legal retention periods and for the purposes stated in the Privacy Policy.

We suggest getting into the habit of glancing at the log once a month: an unfamiliar device, an unusual hour or a settings change you do not remember is the easiest way to catch a problem early.

Incident support

If you notice unauthorised activity on your account, write to [email protected] or call your personal manager. Putting "Security" in the subject and giving the time of the event speeds things up. Support channels are available 24/7 (email and callback requests are handled every day, weekends included).

When a report is received the account is locked straight away if needed and open sessions are ended. The case is escalated to the security team, we contact you by email or phone during the review, and the findings are explained to you at the end. Our reply time is usually usually within one working hour.

Security is a shared responsibility. We protect the infrastructure; you contribute with a strong password, 2FA switched on and careful API management. No measure can remove risk entirely. Please also read the Risk disclosure.

Let us set up your security together

Once your account is open, your personal manager helps you configure 2FA and API permissions step by step.

Create Free Account