Security
Nine layers around your account
Security at Deft Swaphaldine is part of the architecture, not a coat of paint applied at the end. This page walks through the nine layers guarding your account, your data and your funds, and the share of the work that is yours. Anything still murky afterwards goes to the front of
A closing thought on security as a habit rather than a feature: every layer on this page works only while it is actually switched on, which is why the two actions that matter most are also the two that take the least time, enabling 2FA today and reading login alerts when they arrive rather than tomorrow.
the support queue, because security questions are the one category that never waits in line.2FA / MFA
Second factor by authenticator app, with a verified recovery path.
Encryption
Protected in transit and at rest, keys rotated on schedule.
Anti-fraud
Official domains and a match-code in every message.
1. Two-factor authentication (2FA / MFA)
Switch on the second factor on day one and the arithmetic of account theft collapses: a leaked password alone opens an unprotected account in seconds, while password plus authenticator code demands your physical device as well, which moves the attempt from trivial to pointless for nearly every scam in the wild. Any reputable app works, several devices can hold backup registrations, and SMS as the only factor is the weakest option given SIM-swap attacks, though a weak factor still beats none at all where it is genuinely the only choice.
Lose the device and recovery slows down deliberately: a document-based identity check stands between the old factor and the new, so nobody swaps your security by pretending to be you. Once approved, the team clears the stale factor and you register the replacement in minutes. Print the backup codes when 2FA is enabled, or store them in a password vault; they resolve most emergencies without any waiting room.
2. Encryption of data
Everything travelling between your browser and the platform rides TLS, so intercepted traffic reads as noise. At rest, the sensitive records, identity files and account details, stay encrypted in storage, with read access granted strictly by role. The scheme covers the authentication, verification and trade-logging systems, keys rotate on a published cycle, and internal traffic between platform systems carries the same protection so no internal hop becomes the quiet weak link.
Key custody is central by design: reaching the key store requires dual authorisation, which means a single stolen credential cannot expose stored data even from the inside. Rotation schedules are published internally and audited, and keys never travel to staff laptops or personal storage under any circumstance.
3. Fraud and phishing protection
Official Deft Swaphaldine mail leaves only from our own domains; a near-identical domain with one character shifted is the classic scam tell. Every transactional email carries a personal match-code you compare against the code stored in your account: codes differ, message not ours. Three fast checks unmask nearly every fake, official-domain sender, matching code, no request for secrets, and failing any single one settles the matter.
We will never ask for your full password, a 2FA code or complete card details by phone or email. Receive such a request in our name? Do not reply; forward it to [email protected]. Reports pay forward, too: most domains in the takedown log began as a single client forward, and the pattern you flag protects the next account holder who would have received the same message.
4. Login notifications
Each sign-in from a device your account has never met fires an email with date, time and approximate location. We also flag the unusual: strings of failed passwords, or access from a country absent from your history. Since the alarm is only as good as its bell, the registered email deserves its own strong password and provider-side 2FA wherever offered, because a neglected inbox delays exactly the warnings you most want to see quickly.
Alert for a login that was not you? Change the password on the spot, close the open sessions in settings and confirm 2FA is active. If the stated location is impossible, change your registered email password too, that inbox being the master key to recovery.
5. Device and session management
The security panel lists every live session with its device, operating system and last activity, and ends any session, or all of them, without touching the password. Sessions lapse on their own after inactivity, and saved logins die when the password changes or the second factor resets. On shared machines, skip "remember this device" and sign out when finished, the two habits that cover the rest.
6. Account recovery
Password resets use a single-use link that expires quickly and works exactly once. The heavier changes, replacing the registered email or losing the second factor, pass through document-based identity verification before anything moves. During recovery, withdrawals pause briefly: the hold exists so an intruder cannot empty the account while the rightful owner retakes the keys, and it lifts the moment verification completes.
7. API key permissions
Keys connecting the platform to exchanges are born minimal: read data and place orders. Withdrawal, the third scope, stays disabled and is never required for the platform to operate. Every key accepts an IP restriction and instant revocation, so give keys descriptive names ("swaphaldine engine"), test them, date them and retire anything idle beyond ninety days; the panel shows each key's age, turning the monthly review into a read-and-confirm pass rather than a chore.
8. Audit history
Your account keeps a complete ledger of events, logins, integration connections, strategy changes and configuration edits, each line timestamped, and it is the raw material for reconstructing anything that looks off. The same trail is retained server-side for incident investigation and compliance obligations. Something in the history you do not recognise? Tell support immediately: the account freezes and a review opens on the spot.
9. Incident support
Suspect unauthorised access or odd behaviour? Email [email protected] with subject "incident"; a preventive freeze while we investigate is available on request and is the standing recommendation whenever the doubt is serious. The incident channel acknowledges receipt automatically within minutes, the first proof the report landed somewhere with a person attached.
Communication follows a fixed sequence: receipt confirmed, immediate measures applied, and at close a summary of cause and correction. When reporting, include the time you noticed, the device and network involved and any suspicious message received beforehand; each of those
One practical addition for anyone keeping notes: record the reference number every incident exchange gives you, because a single number pulls the entire thread in one move for whoever picks the case up next, trimming hours off conversations that would otherwise restart from zero each time.
details shortens the investigation and helps shield neighbouring accounts from the same attempt.