Protect the account.
Limit the exposure.
Nine safeguards to review before connecting money, devices or third-party tools. This website collects enquiries; security features inside a trading account depend on the external provider and must be confirmed with it.
Know which system
you are protecting.
An encrypted website connection protects data in transit, but it does not establish that an investment provider is legitimate. Account authentication, custody controls and trade permissions are separate questions.
The points below are a verification checklist, not a claim that every named feature has been implemented by Wexmoraine or an unnamed broker.
-
Multifactor authentication
Ask whether the provider supports an authenticator app, hardware security key or SMS, and whether MFA is compulsory for login and withdrawals. Store recovery codes separately from your device. Confirm how a lost authenticator is replaced and whether a recovery request triggers a withdrawal hold.
-
Encryption and its scope
Use the HTTPS version of this site and reject browser certificate warnings. Ask the account provider which records are encrypted at rest, who manages access and whether backups receive the same protection. No encryption-at-rest certification has been supplied for this website, so none is asserted here.
-
Fraud and phishing checks
The official website origin is https://wexmoraine.com and the published support address is [email protected]. Enter the address yourself rather than following an unexpected login link. Ask any provider whether it offers a user-selected anti-phishing code; this website does not claim to issue one.
-
Login notifications
Check whether a provider can notify you by email or push when a new device signs in or account details change. Keep notification channels current and review unfamiliar activity promptly. An absent alert is not proof that an account is safe.
-
Devices and active sessions
Review the provider’s active-session list and revoke access for devices you no longer use. Ask how long inactive sessions remain open and whether changing a password ends existing sessions. Avoid maintaining a trading session on a shared computer.
-
Account recovery
Start recovery through the provider’s published support route, not a social-media helper. Identity checks may be necessary before credentials can be reset, and sensitive changes may temporarily restrict transfers. The enquiry form on this website cannot restore access to an external account.
-
API-key permissions
A read-only connection can inspect data; a trading key can create orders; a withdrawal-enabled key can move assets. Grant the smallest permission set needed and use IP restrictions where offered. Revoke unused keys and never paste secrets into this website’s registration form.
-
Audit history
Look for records of sign-ins, new integrations, strategy changes and security-setting updates. Export important events with timestamps so that a provider can investigate a discrepancy. A dashboard total alone is not a complete transaction or access record.
-
Incident support
For a suspected account compromise, contact the account provider immediately and request the appropriate session, API or withdrawal restriction. Report website impersonation to [email protected] with the suspicious address and time. Ask for a case reference and an agreed update channel; an immediate response time has not been confirmed.
Security is not a return guarantee.
Investments can lose value. A financial services licence is not insurance against trading losses. Do not assume that shares, cryptoassets or money sent to a platform are covered by an Australian government guarantee; check the legal account holder, custodian and applicable arrangements.
For an Australian financial service, verify the provider’s ASIC authorisations and ask whether an eligible complaint can be taken to AFCA. Those checks address different responsibilities from password security and do not eliminate market risk.