Security at Forge Capmoor
Your account holds personal details and access to trading. We protect it in layers, and we explain each layer here so you know what is switched on, what is optional and what you can do yourself.
1. Two-factor authentication
Two-factor authentication (2FA) asks for a second proof, such as a code from an authenticator app or a text message, on top of your password. We support both methods and strongly recommend an authenticator app, because text messages can be intercepted through SIM-swap fraud.
2FA is required before you can withdraw funds and optional for viewing your dashboard. If you lose your second factor, use the recovery steps in section 6 below.
2. Encryption
Data is encrypted in transit using TLS whenever it moves between your device and our servers, and encrypted at rest for personal details and stored credentials. Passwords are never stored in readable form; only salted hashes are kept.
Encryption applies to the website, the dashboard, the API connections we make on your behalf and our internal databases. Access to keys is limited to the small number of systems and staff who need it.
3. Protection from fraud and phishing
Our only official website is forge-capmoor.co.uk, and our official email address is [email protected]. Messages from any other domain are not from us. Legitimate messages never ask for your password, your 2FA code or your API secret.
You can set an anti-phishing code in your account settings. When set, every genuine email from us includes that code, and any email without it should be treated as suspect. See the fraud warning.
4. Login notifications
We send an email, or a push message if you use the app, when your account is accessed from a new device or location, when a password or 2FA setting changes and when we notice activity that looks unusual, such as repeated failed sign-ins.
If you did not do it, change your password straight away and contact your manager or [email protected]. We can lock the account within minutes.
5. Devices and sessions
The Sessions page lists every device signed in to your account, with its approximate location and last activity. You can end any session, or all of them at once, whenever you like.
Sessions end automatically after a period of inactivity, and a fresh sign-in is required before sensitive actions such as changing your withdrawal details.
6. Account recovery
If you cannot sign in, start recovery from the sign-in page. We verify your identity with the email address on file, and for higher-risk cases we ask for the identity documents you provided at registration or a live check.
Recovery takes longer than a normal login by design. Where we cannot confirm who you are, we will not restore access, and withdrawals may be blocked for a cooling-off period after a recovery.
7. API key permissions
When you connect an exchange, you create an API key on the exchange with the rights you choose. There are usually three levels: read (see balances and orders), trade (place and cancel orders) and withdraw (move funds out).
We ask only for read and trade rights. Do not enable withdrawal rights on a key used with our platform, and use the exchange's IP allow-list where it is offered. If a key is ever exposed, delete it on the exchange at once.
8. Audit history
Your account keeps a log of sign-ins, exchange connections, changes to strategies and changes to settings, each with a date, time and device. You can review it at any time to confirm that everything that happened was you.
The same log helps our team investigate if you report a problem, and it is retained in line with the periods set out in our Privacy Policy.
9. Incident support
If you suspect a breach, contact your personal manager or email [email protected] with the subject line "Security incident". Tell us what you noticed and when, but never send passwords or codes.
We can suspend your account, revoke sessions and pause strategies as soon as you ask. We then escalate to our compliance and technology teams, keep you updated by email at each stage, and, where the law requires, report the incident to the relevant authority, such as the ICO.
Keeping your own account safe: a checklist
Security works best when we and you each do our part. We run the systems, monitor for threats and act on your reports. You control the passwords, the devices and the API keys. These habits stop the great majority of account takeovers we see across the industry:
- Use a unique, long password. A passphrase of four or more unrelated words is better than a short password with symbols, and a password manager makes it easy to have a different one everywhere.
- Switch on an authenticator app. It takes two minutes and blocks most attacks that rely on a stolen password.
- Check the address bar. Type forge-capmoor.co.uk yourself or use a bookmark rather than following links in messages.
- Never share a code. Nobody from our team will ask for a one-time code, password or API secret, not on the phone, by email or in a chat.
- Keep devices updated. Install operating system and browser updates and avoid signing in on shared or public computers.
- Review sessions and the audit log monthly. If you do not recognise something, end the session and change your password.
What happens if your account is accessed without permission
Speed matters. Tell us as soon as you notice, and we will suspend the account, end all sessions and pause strategies while we investigate. We compare the audit log against your account of events, and where an exchange key was involved we will tell you which key to delete. We cannot always recover funds that have already been moved out, which is one reason we recommend keeping withdrawal rights off API keys and enabling 2FA.
Where the incident involves personal data we assess whether it must be reported to the Information Commissioner's Office within 72 hours and whether you need to be told directly, as the UK GDPR requires.
What security cannot do
These measures reduce the chance of unauthorised access. They do not protect you from market losses, and no system is completely immune to attack. Cryptoassets are not covered by the Financial Services Compensation Scheme (FSCS). Cash held in a UK bank account may be protected by the FSCS up to its limits, subject to the bank's own status, but that protection does not extend to trading losses.
Security is also not static. We review our controls regularly, test them with independent specialists, apply software updates promptly and train staff to recognise social-engineering attempts. When we change how something works, for example the way sessions expire or which second factors we accept, we publish the change here and tell affected clients in advance wherever we can.
If you ever want to report a weakness you have found in our website or platform, please email [email protected] with the subject "Vulnerability". We take responsible reports seriously, investigate them promptly and will not take action against anyone who acts in good faith, does not access other people's data and gives us reasonable time to fix the issue.
Finally, remember that security settings protect the account, not the market. Read our risk disclosure for the risks that security controls cannot address, and the KYC and AML policy to see how identity checks protect you and other clients.