Security
We hold information about you, not your money. This page sets out how that information is protected, what axplusb will never ask you for, and how to report anything suspicious.
1. Our security model
The most important security property of axplusb is structural: we are an advisory business and we never hold client money or securities. Your assets sit in an account in your own name, and we have no power to move them — see safeguarding. Even in the worst case for us, nobody can instruct a transfer of your portfolio through axplusb.
What we do hold is information: your risk profile, your contact details, the identification documents required by law, and the record of the advice we gave you. Protecting that is what this page is about.
2. Measures we apply
- Encrypted transport. www.axplusb.eu and media.axplusb.eu are served over HTTPS; certificates are renewed automatically.
- A static public website. This site has no database and no login behind it, which removes an entire class of attack from our public surface.
- Separation. Client records and research infrastructure are kept apart from the public website.
- Least privilege. Access to client information is limited to the people who need it for their work.
- Patching and monitoring. Servers are kept up to date and access logs are retained for a technical period for security purposes.
- Vetted providers. Hosting, email and storage providers are bound by written data-processing agreements. The current list is to be confirmed.
The formal information-security policy, including the certification standards followed, if any, is to be confirmed. We do not claim certifications we do not hold.
3. What we will never ask you
- We will never ask for the password, PIN or one-time code of your bank or brokerage account.
- We will never ask you to transfer money to an account belonging to axplusb, to a member of staff, or to any “safe account”.
- We will never ask for remote control of your computer or phone.
- We will never promise a guaranteed return, and we will never pressure you to decide immediately.
- We will never send you new bank details for fees by an unsolicited email.
If you receive such a request in our name, it is not from us. Report it — see section 6.
4. Our official channels
- WEBSITE
- www.axplusb.eu
- PUBLICATION
- media.axplusb.eu
- EMAIL DOMAIN
- @axplusb.eu — for example e.grigorian@axplusb.eu
Anything on a look-alike domain, a free email address, or a messaging account that is not confirmed through one of the channels above should be treated as untrusted.
5. How to protect yourself
- Turn on two-factor authentication with your broker and your email provider — email is the key to everything else.
- Use a unique password for your brokerage account, kept in a password manager.
- Check the sender's full address, not the display name, before acting on a message about your money.
- Never approve a trade you did not expect. Our recommendations always arrive through the agreed channel and can be confirmed by contacting us.
- Review your broker statements and confirmations against the advice you accepted.
6. Reporting a security issue
If you find a vulnerability in our websites, or you receive a message impersonating axplusb, write to e.grigorian@axplusb.eu with the subject “Security report”. Include what you found, how to reproduce it, and the date and time.
We acknowledge security reports as a priority, we will keep you informed of the outcome, and we will not pursue researchers who report a genuine issue in good faith, act only against their own data, and give us a reasonable opportunity to fix it before disclosing. We do not currently run a paid bug-bounty programme.
7. If a breach occurs
If personal data we hold is compromised, we investigate, contain the incident, and record it. Where the law requires it we notify the competent data protection authority, and where the incident is likely to present a high risk to you we notify you directly and explain what to do.
Your rights over your data, and how to exercise them, are in our privacy policy.