Account security at SQM Financerra

These are the nine measures we use to protect your account, and the ones you can switch on yourself. None of them removes risk completely, but each one closes a specific route to trouble: stolen passwords, logins from unknown devices, API permissions that are too broad, or fake messages pretending to be us.

Shield in the colours of Chile with a padlock over a network of connections

1. Two-step authentication (2FA)

On top of your password, the account can ask for a temporary six-digit code generated by an authenticator app on your phone. We accept the commonly used apps that follow the TOTP standard. Text messages are not our main method, because they are easier to intercept.

The second step is mandatory to request a withdrawal and to change the email, the phone number or the permissions of an API key. For signing in it is optional, but we strongly recommend it. When you switch it on you receive backup codes: keep them away from your phone, because they are the recovery route if you lose it.

2. Data encryption

Information travelling between your browser and our servers is encrypted with TLS, the same protocol banks use for their websites. If the address does not start with https or the browser shows a warning, do not continue and tell us.

We also separate environments: the systems that process your data are isolated from the ones that run the public website, so a problem on one does not automatically reach the other. Personal data and verification documents are stored encrypted at rest, with keys held separately from the information. Internal access depends on the job: support sees what it needs to help you and cannot see your passwords or your second-step codes, which we never store in readable form.

3. Fraud and phishing protection

Our only official domain is sqm-financerra.com and our emails end in @sqm-financerra.com. If you get a message from another domain, a shortened link or an unknown number claiming to be from the company, do not open it and do not hand over any data.

Scammers often copy our colours and logo, which costs them nothing, so appearance alone proves nothing. You can set a personal security code in your profile. If you do, every genuine email includes it, and a message without that code should be treated as fake. We will never ask for your password, your second-step codes or API keys with withdrawal permission. More in the fraud warning.

4. Login alerts

Every time someone signs in to your account from a device or a place we have not seen before, we send you an email with the approximate time, the type of device and the estimated city. If you recognise it, you do not have to do anything.

If you do not recognise it, the email includes a link to close all sessions and lock the account at once. We also warn you when we detect suspicious activity, such as many failed password attempts or configuration changes within a few minutes. Keep your own email protected with its own second step, because the alerts travel through it.

You choose which alerts to receive and how often. We suggest keeping login and security alerts permanently on, since they are rare when everything is fine and invaluable when it is not.

5. Device and session management

In the security panel you see the list of active sessions with the device, the browser and the date of last use. You can close one specific session or all of them with a click, and access is revoked immediately.

Inactive sessions close on their own after a period without use, and the time is shorter when a sensitive operation is pending. If you use a shared computer, always sign out when you finish and do not tick the option to remember the device.

6. Account recovery

If you lose access, you can use your backup codes or the recovery link sent to your registered email. When that is not enough, support starts an identity check: we compare your ID card and a live photo with the details you opened the account with.

For safety, recovery has limits. After access is restored, withdrawals stay on hold for a protection period, and the account may ask for a new verification if we spot differences. It is slower than a normal reset, and deliberately so: it protects your money from anyone trying to take over your account.

7. API key permissions

To trade on your exchange, the platform connects through an API key that you create on that exchange. The key has permissions that you choose: reading balances and history, trading orders and, on some exchanges, withdrawing funds.

We only need read and trade. We neither ask for nor accept keys with withdrawal permission, so nobody can take money out of your exchange through the platform. If a message ever asks you to enable withdrawals "to speed things up", treat it as fraud, whoever it claims to come from. We recommend restricting the key to our IP addresses when the exchange allows it and revoking it from the exchange as soon as you stop using the service.

8. Audit history

We record and show you the important events on the account: logins, exchange connections, permission changes, strategies switched on or paused and changes to the risk settings. Each event carries a date, a time and a device.

You can download the history whenever you need it, for example to go through with your manager something you do not remember doing. Records are kept for the period the rules require and are protected against changes, including by our own team.

9. Incident support

If you suspect someone accessed your account, write to [email protected] or ask your personal manager to lock the account. A lock stops strategies, closes sessions and holds withdrawals until we verify your identity.

After the lock, the support and compliance team reviews the history, explains what happened and what can be done, and escalates the case when appropriate, including to the competent authorities. We keep you informed of every step through the channel you choose. In the meantime, change your email password and revoke your API keys from the exchange.

Security is a shared responsibility: we protect the platform and you protect your devices, your email and your keys. No system is infallible. Also read the risk disclosure before trading.

Six habits that protect your account

Technical measures work best when combined with simple routines. This is the short list we give everyone on their first call.

  • A unique passwordUse a long password you do not reuse on other sites, ideally kept in a password manager.
  • Second step everywhereSwitch it on in the platform, in your email and in your exchange. One weak link is enough to open the others.
  • Distrust urgencyFrauds say something expires today. We will never ask you to decide under pressure.
  • Devices up to dateKeep the system, the browser and the authenticator app updated, and do not install remote-control software at someone else's request.
  • Check your historySpend a minute each week looking at active sessions and account events.
  • Revoke what you do not useIf you stop using an API key, a device or a strategy, remove it to reduce what could go wrong.