ACCESS CONTROL

Security is also
something you configure.

Protect your credentials, review your connections and prepare a response before an incident. This guide from Ridge Growantion distinguishes good practices from the functions you must confirm with your provider.

No third-party infrastructure is certified here. The availability of each control depends on the account, the integration and the provider you contract. No measure completely prevents losses, intrusions or outages.

1. A second factor for signing in

A unique password reduces the risk of reuse, but it can still be exposed. When the provider allows it, turn on multi-factor authentication with an authenticator app or a security key. Confirm whether the second factor is required only when signing in or also when changing data and requesting withdrawals. Do not assume it is active just because you completed a registration on this site.

Keep recovery codes in a place separate from your usual device. If you lose your phone, do not share a code with someone who calls you to “reactivate” the account. Start the recovery yourself through the official channel. Replacing the factor may require verifying your identity and can create a period in which sensitive operations are restricted; ask for the procedure before you need it.

  • Use a password manager with its own lock.
  • Protect the email linked to the account as well.
  • Do not photograph codes to send them by messaging apps.

2. Encryption and the reach of protection

In production, the connection to the site must use HTTPS. The padlock in the browser indicates an encrypted connection with that domain, but it does not certify the solvency or the financial authorisation of the operator. Check the full address and avoid forms embedded in pages of unknown origin. An infected device can expose information before transport encryption protects it.

Encryption at rest, backups and key management belong to the systems that receive the data. Algorithms and certifications that have not been documented are not published here as audited facts. Before sending sensitive documents, ask who stores them, who can access them, what they are used for and how long they are kept. You will find the general criteria in the privacy policy.

3. Authentic messages and impersonation

The official origin of this site is https://ridge-growantion.com. Compare every letter of the domain, especially in advertisements, search results and messages that imitate a support reply. A visible name or a logo does not authenticate the sender. If a representative switches channels and asks for an unexpected payment, stop the exchange and check through the email published on this page.

There is no accredited anti-fraud code for this site. If the provider offers a personal code in its messages, activate it from its dashboard and verify how it works. Never hand over passwords, temporary codes, recovery phrases or remote access to your device. Requests for money to “unlock gains” need independent verification, even when they include documents with an official appearance.

4. Access and activity alerts

Sign-in alerts by email or notification, where available, help detect a new device. Check the time, the approximate location and the browser type without reading a geolocation as definitive evidence. A mobile network or a corporate connection can show a different city. An unknown operation, on the other hand, deserves an immediate review of the session and permissions.

Sign in by typing the provider's address, not from the link in a suspicious alert. Check whether you can turn on alerts for password changes, API keys, beneficiaries and withdrawals. If you do not receive notifications, check your email filters and the state of your preferences. The absence of an alert does not prove that the account is protected or that an instruction was not executed.

5. Devices and open sessions

Check the provider's session list and close the ones you do not recognise. A session can remain active even after you close a tab; use the sign-out option when you finish on a shared device. Also review access to your email and to any linked account. A new password does not always revoke all existing connections, so it is worth checking both actions separately.

Ask whether sessions expire automatically after inactivity and whether a session can authorise operations without signing in again. Lock the device when you are not using it and keep the browser and system up to date. Avoid saving credentials on other people's devices. If you sell or lose a phone, revoke its access before setting up a new one and verify that notifications still arrive on a channel under your control.

6. Account recovery

Recovery must verify that the person requesting access is the account holder. Describe the problem, the previous contact detail and when it stopped working, without attaching documents on your own initiative. The team should indicate a suitable channel if it needs further evidence. A serious process can take longer than a normal password change, especially if the email address and phone number were changed at the same time.

Request a case number and keep the instructions you receive. Do not open contradictory requests from several identities or accept help from a supposed recovery agent who charges in advance. During the review, some functions may be limited to prevent a third party from withdrawing funds. Ask for the scope of that restriction and what is missing to lift it to be explained, without expecting immediate access as an automatic right.

7. API key permissions

An API key lets one application communicate with another account. Reading, order execution and withdrawal are separate powers. To check balances or prices, choose read-only; if a function needs to trade, check which orders it can send. Do not enable withdrawal for an analysis tool. A key with excessive permissions widens the possible damage even if your main password has not been leaked.

Permissions worth distinguishing
Permission What it allows Precaution
Read View enabled information Check what data is exposed
Trading Send orders Limit scope and supervise
Withdrawal Move assets out of the account Do not enable for analysis

Create one key per integration, note its purpose and revoke it when you stop using it. If the provider supports limits by network address, understand their requirements before turning them on. Do not paste secrets into a support query or a screenshot. If a secret is exposed, revoke the key and review the history; deleting the message where it appeared does not invalidate the credential.

8. A history for reconstructing changes

A useful log identifies accesses, connections, strategy modifications and permission changes with date and time. Confirm which events the dashboard records, how long they can be consulted and whether they can be exported. Compare the log's time zone with Bangladesh Standard Time so you do not attribute an order to the wrong moment. Saving an isolated screenshot does not replace the complete detail of the operation.

When you detect a difference, note the identifier, instrument, status and parameters in force. A strategy modified after an operation does not necessarily explain the earlier behaviour. Keep the context and avoid changing settings without recording what was there. The history serves investigation, but it does not guarantee that all malicious activity becomes visible or that an operation can be reversed.

9. What to do in an incident

Write to [email protected] with the subject “Security incident” and a brief description. If the problem affects the custodian or the bank, contact it as well through its official channel to request the available measures. This site cannot on its own freeze funds held at an external entity or cancel orders already executed.

Preserve messages and identifiers, change credentials from a trusted device and revoke compromised connections. The order can vary depending on whether there is a transfer in progress or an active access. Ask for confirmation of receipt and a status update without sending secrets. The published response time is [CONFIRMED RESPONSE TIME]; no emergency response is promised unless it has been confirmed.

Recognise a possible scam