Security you can participate in
A secure account needs sound provider controls and careful choices by its owner. This guide explains the safeguards to look for, how to use them and what to do when something seems wrong.
1. Two-factor and multi-factor authentication
A second factor makes a stolen password less useful. Common methods include an authenticator app, a hardware key or a one-time code. An app or hardware key is preferable to a code delivered by an easily compromised communication channel when the provider supports it.
Ask whether a second factor is required for login, payment changes, API creation and withdrawals, and which recovery process applies if a device is lost. Do not disable protection for convenience after setup. Keep backup codes in a separate, protected place rather than in a screenshot on the same phone.
Availability of a particular method depends on the actual account provider. This site does not assert that every method is active in every connected service. Check the security settings inside each service you use and record how to revoke access if your device is stolen.
2. Encryption and data handling
Financial and identity information should be protected in transit between a visitor's browser and the service through modern transport encryption. Sensitive records should also be protected at rest with access limited to people and systems that need them. Encryption is one layer; it does not make weak permissions or a stolen password harmless.
Ask the legal provider which systems store your documents, how those systems restrict access and how a data incident would be communicated. Avoid sending identity documents over an unverified chat account or ordinary email unless the provider explains a secure process for doing so.
The Privacy Policy explains the information this site may collect from inquiries and the categories of service providers that may receive it. Review the provider's separate privacy terms when an account is opened with another legal entity.
3. Fraud and phishing protection
Check that you are on https://tenardship.org before entering details. A near-match address, unexpected attachment, shortened link or message urging immediate payment deserves caution. A familiar logo is easy to copy and is not proof that a page or caller is authentic.
Official communication should not require you to disclose a password, one-time code, recovery phrase or remote-control access. If a provider offers an anti-phishing code in its emails, set it up and verify that it appears correctly. Do not rely on a sender name alone because email display names can be forged.
Use the fraud warning to collect the right evidence if you see a clone. Type the support email from this site yourself rather than replying to the suspicious message. Ask the provider to confirm a payment instruction through an independently verified channel.
4. Login and activity notifications
A notice about a new device, unusual location, password reset or changed payment destination can give you time to act. Email or push delivery may be delayed or missed, so a notification is a warning channel rather than a complete record of account activity.
Keep your contact address current, protect that mailbox and review its forwarding rules. If a sign-in notice is unexpected, go to the service directly, change credentials, revoke sessions and contact support. Avoid using a link in the notice until you have checked it independently.
Where the provider offers alert preferences, keep the critical ones enabled. A flood of low-value messages can make a real security event easier to miss; choose settings that highlight account access, permission changes and withdrawals.
5. Devices and sessions
Active-session views help you see which devices can access an account. Review the list after travel, a device sale or an unexpected alert. Sign out of sessions you do not recognize and remove devices that are no longer in your control.
Automatic session expiry reduces the time an unattended device stays available, but it cannot replace a screen lock. Avoid saving credentials on a shared computer. If you use a public network, verify the connection and avoid entering sensitive information through a captive page or an unexpected prompt.
Different connected services maintain their own sessions. Signing out of the Tenardship site may not revoke a session at an exchange or payment provider. Review each service separately when you suspect compromise.
6. Account recovery
Recovery is a common target for fraud because it can bypass a lost password. A provider may ask for identity evidence and may restrict sensitive functions while a recovery request is reviewed. Those checks protect the account holder but can also delay legitimate access.
Begin recovery only from a verified site or a support contact you found independently. Ask how the provider confirms your identity, how long a restriction can last and when you will receive an update. Never pay an unofficial "unlock" fee or send documents to a personal messaging account.
After access is restored, change the password, replace compromised second-factor methods, review authorized devices and inspect recent activity. Notify the provider promptly if a transaction or permission change occurred without your approval.
7. API-key permissions
An API key can let a connected tool read balances, inspect market data or place trades, depending on its scope. Those permissions should be explained separately. A read-only key does not need the ability to execute orders, and an analytical view should never require withdrawal access merely to display information.
Create a separate key for each connection when the provider permits it. Limit it to necessary functions, use any available IP restrictions and remove it when the connection is no longer needed. Store the secret securely; do not paste it into a support chat or email.
If the account behaves unexpectedly, revoke the key at the source exchange first, then investigate the platform logs. Revoking a key can pause a tool, so understand the operational effect before reconnecting with a new one.
8. Audit history
An activity record should help you reconstruct logins, connection changes, strategy settings and account actions. Look for timestamps, device or channel information and a clear description of what changed. A single balance number cannot explain how a position or payment reached its current state.
Review the history after a configuration change and periodically while automation is active. Save confirmations of important actions outside the platform. If two records disagree, ask the provider to investigate using transaction references and source-system records.
Audit records may have different retention periods across services. Ask how long they remain available and how to obtain a copy for a complaint. The Privacy Policy explains general data-handling principles for this website.
9. Incident support
If you suspect unauthorized access, stop interacting with the suspicious message, revoke affected credentials where you can and contact [email protected]. Provide the date, affected account identifier, event description and transaction references. Do not send passwords, full payment-card numbers or recovery phrases.
The support team should acknowledge the report, route it to the appropriate specialist, explain any temporary account restriction and provide updates as facts are confirmed. The exact timing depends on the investigation and the legal provider involved. Keep a written record of communications and ask for a case reference.
If a third-party exchange, bank or card is involved, contact that provider directly as well. An incident at one service can affect another account through reused credentials. Change them independently and watch for related phishing attempts after a report.
Canadian asset-protection context
Eligible deposits at a CDIC member institution may be insured under CDIC rules. Eligible property at a CIPF member dealer may be protected if that dealer becomes insolvent. Cryptocurrencies are not CDIC-insured, and crypto assets themselves are not CIPF-eligible. Confirm the identity and membership of the institution holding each asset before assuming any protection applies. The distinction between an eligible cash deposit, a security and a crypto asset matters more than the visual label on a dashboard.
Neither security settings nor investor-protection schemes remove market risk. Use the risk disclosure to assess how a trade or automated strategy can lose value even when account access remains secure.