Security at Gebvax AI
Multi-factor authentication adds a second proof after the password, normally an authenticator code or supported device confirmation. We strongly recommend enabling it from the first session. Recovery requires identity checks and may temporarily restrict sensitive actions to prevent social-engineering abuse.
Multi-factor authentication
Multi-factor authentication adds a second proof after the password, normally an authenticator code or supported device confirmation. We strongly recommend enabling it from the first session. Recovery requires identity checks and may temporarily restrict sensitive actions to prevent social-engineering abuse.
Multi-factor authentication adds a second proof after the password, normally an authenticator code or supported device confirmation. We strongly recommend enabling it from the first session. Recovery requires identity checks and may temporarily restrict sensitive actions to prevent social-engineering abuse. This point should be read together with the current account information and any provider terms displayed before an instruction is confirmed. Keep a copy of material notices and ask support when a fact is unclear.
Encryption
Supported browser traffic is encrypted in transit, and sensitive stored information is protected using access-controlled systems. Encryption reduces exposure but does not protect a compromised device or a password shared with another person. Keep the browser and operating system updated.
Supported browser traffic is encrypted in transit, and sensitive stored information is protected using access-controlled systems. Encryption reduces exposure but does not protect a compromised device or a password shared with another person. Keep the browser and operating system updated. This point should be read together with the current account information and any provider terms displayed before an instruction is confirmed. Keep a copy of material notices and ask support when a fact is unclear.
Fraud and phishing protection
Official communication will not ask for your password or one-time authentication code. Check the full domain before signing in and treat unexpected payment instructions as suspicious. A support colleague can verify whether a message is genuine through [email protected].
Official communication will not ask for your password or one-time authentication code. Check the full domain before signing in and treat unexpected payment instructions as suspicious. A support colleague can verify whether a message is genuine through [email protected]. This point should be read together with the current account information and any provider terms displayed before an instruction is confirmed. Keep a copy of material notices and ask support when a fact is unclear.
Login alerts
Security notices can be issued after a sign-in from a new device, a material account change or activity that differs from the established pattern. Review alerts promptly. If an event is not yours, change the password from a trusted device and contact support.
Security notices can be issued after a sign-in from a new device, a material account change or activity that differs from the established pattern. Review alerts promptly. If an event is not yours, change the password from a trusted device and contact support. This point should be read together with the current account information and any provider terms displayed before an instruction is confirmed. Keep a copy of material notices and ask support when a fact is unclear.
Devices and sessions
The account view is designed to show active sessions and let access be revoked. Sessions may expire automatically after inactivity or following a security event. Remove old devices, avoid shared computers and sign out where other people can access the browser.
The account view is designed to show active sessions and let access be revoked. Sessions may expire automatically after inactivity or following a security event. Remove old devices, avoid shared computers and sign out where other people can access the browser. This point should be read together with the current account information and any provider terms displayed before an instruction is confirmed. Keep a copy of material notices and ask support when a fact is unclear.
Account recovery
Recovery begins through support and includes checks proportionate to the requested access. Staff may compare verified account details and request fresh evidence, but will not ask for a full password. Trading, payment or profile functions can remain limited until the review is complete.
Recovery begins through support and includes checks proportionate to the requested access. Staff may compare verified account details and request fresh evidence, but will not ask for a full password. Trading, payment or profile functions can remain limited until the review is complete. This point should be read together with the current account information and any provider terms displayed before an instruction is confirmed. Keep a copy of material notices and ask support when a fact is unclear.
Connection permissions
External connection keys should be limited to the functions genuinely needed, such as read access or trading where supported. Withdrawal permission should remain disabled unless a clearly documented service requires it. Rotate or revoke keys after suspected exposure.
External connection keys should be limited to the functions genuinely needed, such as read access or trading where supported. Withdrawal permission should remain disabled unless a clearly documented service requires it. Rotate or revoke keys after suspected exposure. This point should be read together with the current account information and any provider terms displayed before an instruction is confirmed. Keep a copy of material notices and ask support when a fact is unclear.
Audit history
Security records can include sign-ins, connected services and changes to monitoring or strategy settings. Review the history after receiving an alert and before assuming a change was a system error. Records support investigation but are not a substitute for prompt reporting.
Security records can include sign-ins, connected services and changes to monitoring or strategy settings. Review the history after receiving an alert and before assuming a change was a system error. Records support investigation but are not a substitute for prompt reporting. This point should be read together with the current account information and any provider terms displayed before an instruction is confirmed. Keep a copy of material notices and ask support when a fact is unclear.
Incident support
If you suspect unauthorised access, contact [email protected] immediately with the time, device and nature of the event. Support can route a restriction request, preserve relevant records and explain the next verification step. Never include passwords or one-time codes in the report.
If you suspect unauthorised access, contact [email protected] immediately with the time, device and nature of the event. Support can route a restriction request, preserve relevant records and explain the next verification step. Never include passwords or one-time codes in the report. This point should be read together with the current account information and any provider terms displayed before an instruction is confirmed. Keep a copy of material notices and ask support when a fact is unclear.