Security & trust

Security at every layer

How your account, your documents, and your money are protected — and how you can help keep them that way.

Platform controls

How we protect your account

Security is built into how the platform works, not added at the edges.

Account credentials

Passwords are stored only as one-way hashes, never as readable text. Repeated failed sign-in attempts from the same address are throttled, and password resets expire after a limited time and can only be used once.

Protected requests

Actions that change your account are tied to your signed-in session and validated on the server. Every database query uses bound parameters, and content shown back to you is escaped before it reaches the page.

Money never moves on trust

Deposits and withdrawals are requests, not instructions. Balances are calculated on the server from an approved ledger, so no amount is credited or released from unverified input on a form.

Role-based access

Investor, affiliate, and administrative areas are separated. Each request re-checks the permissions of the signed-in account, so access is decided by the server rather than by which page you can reach.

Recorded administration

Administrative actions such as approvals, status changes, and settings updates are written to an audit log with the account, time, and address that made them.

Document handling

Identity documents are stored outside the public web directory and cannot be opened by a direct link. Uploads are checked by file type and size limits, and are renamed on arrival.

Fraud awareness

What we will never ask you for

If you are ever asked for any of the following, it is not us. Stop, do not reply, and contact us through the details on our contact page.

  • Your password, in an email, a message, or over the phone.
  • A one-time code, reset link, or verification code from your email.
  • Remote access to your computer or phone.
  • Payment to a personal account of an individual member of staff.
  • A "recovery fee" or "release fee" to unlock a balance or withdrawal.
Your part

How to keep your account safe

Use a unique password

Use a long password that you do not use on any other website, and store it in a password manager rather than reusing it.

Check the address bar

Only sign in at tradersonly4u.com, and confirm your browser shows a secure connection before entering details. Links in unexpected messages are the most common way accounts are stolen.

Protect your email

Whoever controls your email address can request a password reset. Secure that account with its own strong password and two-factor authentication.

Review your activity

Check your transaction history and notifications regularly, and tell us immediately if you see something you did not do.

Responsible disclosure

Reporting a security concern

If you believe you have found a vulnerability, or you think your account has been accessed by someone else, tell us as soon as possible at support@tradersonly4u.com. Include what you found, the steps to reproduce it, and the time it happened.

Please report issues privately and give us a reasonable opportunity to respond before disclosing them publicly. Do not access, modify, or delete data belonging to other people while investigating, and do not run tests that degrade the service for others.

Security controls reduce risk but cannot remove it entirely, and no platform can promise that an account will never be compromised. TradersOnly4u makes no claim to any regulatory licence, registration, certification, or compliance approval unless verified details are published by an authorised administrator. Investing involves risk, returns are not guaranteed, and you may lose some or all of your invested capital.