Security
Nine layers, no secret handshakes
Security at Quantum Yellow is designed in, bolted on nowhere. This page details the nine layers around your account and your role in each. Anything still unclear afterwards goes to the front of the support queue, because security questions do not keep.
2FA / MFA
Second factor by app, with a verified recovery path.
Encryption
Protected in transit and at rest, keys rotated on schedule.
Anti-fraud
Official domains plus a match-code in every message.
1. Two-factor authentication (2FA / MFA)
Turn on the second factor on day one and the mathematics of account theft change overnight: with only a leaked password your account opens in seconds, while with password plus authenticator code the attacker also needs your physical device, which moves the attempt from trivial to impractical for the overwhelming majority of scams in circulation.
Lose the device and recovery deliberately slows down: a document-based identity check stands between the old factor and the new one, so nobody swaps your security by pretending to be you. Approved, the team resets the factor and you register the new device in minutes. Print the backup codes when you enable 2FA, or park them in a password vault; they resolve most
On authenticator practicalities: any reputable app serves, several devices may hold backup copies, and SMS as the lone factor is the weak option given SIM-swap attacks, though a weak factor still beats none at all where it is genuinely the only one available.
emergencies without the waiting room.2. Encryption of data
Every byte travelling between your browser and the platform rides TLS, so intercepted traffic reads as noise. At rest, the sensitive records, identity files and account details, stay encrypted in storage with read access granted strictly by role.
The scheme spans the authentication, verification and trade-logging systems, keys rotate on a published cycle, and traffic between internal platform systems carries the same protection, so no internal hop quietly becomes the weak link. Key custody is central, with dual authorisation required to reach the key store itself: a single stolen credential cannot
A word on where alerts land, since the alarm is only as good as its bell: notifications go to the registered email, which earns that inbox its own strong password and provider-side 2FA where offered, because a neglected mailbox delays precisely the warnings you most want to see quickly.
expose stored data even from the inside.3. Fraud and phishing protection
Official Quantum Yellow mail leaves only from our own domains; a near-identical domain with one character moved is the classic scam signature. Each transactional email carries a personal match-code you compare against the code stored in your account: codes differ, message not ours.
We will never ask for your full password, a 2FA code or complete card details by phone or email. Receive such a request in our name? Do not reply; forward it to [email protected]. Three fast checks unmask almost every fake: official-domain sender, matching code, no request for secrets; fail one and it is a scam, full stop. Reports pay
The three-check method deserves its own emphasis because it works in seconds: official-domain sender, matching verification code, no request for secrets. Failure on any single check settles the matter, and the report you file protects the next account holder who would have received the same message.
forward, too, since most domains in our takedown log began as a single client forward.4. Login notifications
Each sign-in from an unfamiliar device fires an email with date, time and approximate location. We also flag the unusual: strings of failed passwords, or access from a country absent from your history.
Alert for a login that was not you? Change the password on the spot, close the open sessions in settings and confirm 2FA is active. If the stated location is impossible, change your
Session hygiene closes the loop with login alerts: after any suspicious notice, the settings page shows every live session with its device and last activity, one click ends the questionable one, and a password change retires every saved login at once, the clean sweep that removes doubt in under a minute.
registered email password too, because that inbox is the master key to recovery.5. Device and session management
The security panel lists every live session, its device, operating system and last activity, and lets you end any session, or all of them, without touching the password.
Sessions lapse on their own after inactivity, and saved logins die when the password changes or the second factor is reset. On shared machines, skip "remember this device" and sign out when done.
6. Account recovery
Password resets use a single-use link that expires fast. The heavier changes, replacing the registered email or losing the second factor, pass through document verification before anything moves.
During recovery, withdrawals pause briefly: the hold exists so an intruder cannot empty the account while the rightful owner is retaking the keys, and it lifts the moment verification completes.
7. API key permissions
Keys linking the platform to exchanges are born minimal: read data and place orders. Withdrawal, the third scope, stays off and is never needed for the platform to operate.
Every key accepts an IP restriction and instant revocation. Name keys so their purpose is obvious ("qy engine"), test them, date them, and retire anything idle beyond ninety days; the panel shows each key's age, which turns the monthly review into a read-and-confirm job.
8. Audit history
Your account keeps a complete ledger of events: logins, integration connections, strategy changes and configuration edits, each line stamped with date and time. It is the raw material for reconstructing anything that looks off.
The same trail is retained server-side for incident investigation and compliance. Something in the history you do not recognise? Tell support immediately: the account freezes and a review opens.
A last word on timing: security questions are the only category support answers out of order, ahead of the queue, because a report that waits a day is a door that stayed open a day. It is also why the incident channel confirms receipt automatically within minutes: acknowledgement is the first proof the report landed somewhere with a person attached.
9. Incident support
Suspect unauthorised access or odd behaviour? Email [email protected] with subject "incident". A preventive freeze of the account while we investigate is available on request and is our standing recommendation whenever the doubt is serious.
Communication follows a fixed sequence: receipt confirmed, immediate measures applied, and at close a summary of cause and correction. When reporting, include the time you noticed, the device and network involved and any suspicious message that preceded it; every one of those details shortens the investigation and helps shield neighbouring accounts.