Security

What actually protects your account.

Not a wall of badges. This page says how your password and your transfer PIN are stored, what you can switch off yourself and how quickly, what is written down about your sign-ins, and who to tell the moment something looks wrong. Where a fact depends on the company operating this site rather than on the software it runs, it is marked as such instead of guessed.

Passwords hashed, never stored readably

A transfer PIN nobody here can read back

Freeze your card yourself, in about a second

How credentials are stored

Two secrets, and what becomes of them.

Both are put through a one-way function before they are written down, so what the database holds cannot be turned back into what you typed — by us, or by anyone who ever got hold of it.

Your password

Hashed before it is stored and never kept in a form anyone can read — including us. If you forget it we can only help you set a new one; nobody here can tell you the old one.

Your transfer PIN

You are asked for it every time you send money, and it is stored the same way. We cannot show you the old one, and neither can anybody else. Transfers are refused until you set one.

Getting back in

A password reset works by sending a link to the email address on your account, and that link stops working after an hour. Nobody reads your old password back to you, because nobody can.

No system is perfectly secure, so we also ask you to protect your own credentials — see the terms.

Read the terms

In your account

Four things you can do without asking us.

Every one of these takes effect when you press it. None of them needs a phone call, and none of them can be undone by anybody but you.

Freeze the card

Freeze it the second you cannot find it. It stops in about a second, nothing else about your account changes, and you can unfreeze it the moment it turns up in a coat pocket.

Freeze my card

Change your password

From your account settings, using the password you have now. You will need the new one to sign back in, on this device and on every other.

Account settings

Check what a payment was

Every movement carries a reference, what it was, where it went and the balance it left behind. It is the quickest way to settle whether a payment you do not recognise is yours.

Your transactions

See what may leave your accounts

Two per-transfer limits apply — one for wire and crypto, one for bank and local transfers — alongside a switch that refuses every transfer before your PIN is even checked. Limits are set by us; ask if you need one raised.

Security settings

What is written down

The record kept about your account.

It is not there to profile you. It is kept so that unauthorised access can be detected and investigated, and so that we can answer you when you ask what happened and when.

Last sign-in

The time you last signed in

Password changes

The time your password was last changed

Email address

Whether it has been verified, and the tokens used to verify it or to reset a password

Two-factor

Whether it is switched on, and its recovery codes

Preferences

Your notification and communication settings

What you did here

The records created by what you do — transactions, requests and support messages

The full list is in the privacy policy

SITE OWNER — REPLACE THIS

Two-factor sign-in is not switched on for customers here.

The account record has fields for two-factor authentication and its recovery codes, and this page deliberately does not promise them, because nothing on the customer side of this site turns them on today — the second factor a customer actually has is the transfer PIN. If your deployment enables a second sign-in factor, describe it here and add it to the account screen. Until it does, do not.

Your money

Held apart from ours.

Your money is held separately from the money that runs the business. It is not used to fund the company, and it does not sit in the same place as the money that pays its bills.

SITE OWNER — REPLACE THIS

Who regulates this business.

Name the authority that authorises and regulates it, and the number a customer can look it up under on that authority's public register. Everywhere else this site says only “the authority named in our terms”, because a theme cannot know which one it is.

SITE OWNER — REPLACE THIS

Which deposit protection scheme applies.

Name the scheme that covers deposits where you operate — FSCS, FDIC, a national deposit guarantee scheme, or none at all — the amount it covers per person, and which of your accounts are eligible. Until it is named as a fact this site holds, the home page's protection badge and the deposit rows on the personal, business, savings and services pages show a generic sample in its place.

Your part

Four things only you can do.

01

Use a password you use nowhere else.

It is hashed here and cannot be read back. But a password reused on a site that is breached is a password somebody already has, and no amount of care at this end changes that.

02

Keep your transfer PIN to yourself.

Nobody here can read it back — including us. So treat any message asking you to confirm it, from anyone, as a fake, however convincingly it is written.

03

Freeze first, ask second.

If a payment or a sign-in was not you, freeze the card before you write to us. Freezing takes about a second and you can undo it yourself; a conversation is neither of those things.

04

Read the receipt before you worry.

Most payments people do not recognise are simply named differently by the shop. The receipt says what it was, where it went and the balance it left behind.

If something is wrong

Tell us straight away.

A card gone, a payment you did not make, an email that does not look right — any of those, at any hour. Freeze the card yourself first if it is the card; it is faster than we are.

Chat

24/7

In the app, or the bubble on this page

Usually under a minute

Phone

24/7

+1 (512) 555-0198

Straight through, no menu

Email

Mon–Fri

support@vantoracapital.today

Within one working day

If you are not satisfied with how we handle it, the complaints procedure sets out what happens next and by when.

Read the complaints procedure

Site owner

What this page deliberately does not claim.

A theme cannot hold a certificate, commission an audit or run a disclosure programme. Everything below is left for the company operating this site to complete — or to leave out, honestly, rather than to imply.

SITE OWNER — REPLACE THIS

Certifications and audits.

If this business holds a security certification — ISO/IEC 27001, SOC 2, PCI DSS — name it here with its scope, the body that issued it and the date of the last audit, and link the certificate itself. Nothing in this software evidences one, so nothing on this page claims one. A seal you have not earned is the fastest way to lose an argument with a regulator.

SITE OWNER — REPLACE THIS

Independent testing.

If your systems are penetration-tested or reviewed by an outside party, say by whom and how often, and what happens to what they find. Say nothing at all rather than “regularly”.

SITE OWNER — REPLACE THIS

Reporting a vulnerability.

Give the address a security researcher should report a problem to, and the terms you offer them for doing it quietly. Without one, somebody who finds a fault in this site has nowhere to send it, and publishing is their remaining option.