Security
How We Protect Your Data
We've implemented systematic processes and procedures for securing and storing user data. We use strong browser encryption, store all of our data on servers in a secure facility, and implement systematic processes and procedures to protect it.
Fraud Protection
Safeguards to guard against unauthorized activity. We are committed to protecting your account from fraud. If you see any unauthorized activity in your account, report it immediately . We'll work with you to address any issues that result from unauthorized use of your account.
Privacy
Respect for your personal data and information. We protect the privacy of your information. For more information, please review our Privacy Policy.
Password Safety
When threat actors hack into a website, passwords are usually the first thing they target. We encourage users to use strong and unique passwords that are not shared anywhere else. We protect user passwords in a variety of ways, storing them in a format called a "bcrypt hash." This is a method for protecting your password in our systems.
Two-Factor Authentication
Two-factor authentication strengthens the security of your account. Typically when you log in to a website, you just need your password. Your password is acting as the first factor in place in order to access your account. With twofactor authentication , you will use your password, and also enter a one-time code from a mobile authenticator application in order to finish logging in. The code is now the second factor in place for account access. Two-factor authentication strengthens the security of your account. Even if an attacker knows your password, they still would not be able to log in unless they also had access to the device where you receive the one-time code. While this adds little friction for legitimate customers, it frustrates attackers. We'll even remember which devices you've logged in with in the past, so that you don't have to keep entering codes when you log in repeatedly with the same device.
Limited Data Access
Employees only have access to customer account information when it is needed for their job (this is called the principle of "least privilege"). This ensures any internal or external threats are minimized.
Encryption
Encryption is a control that can help to protect the confidentiality of data. We use several types of encryption (when data is in transit, and when we store it); the specific encryption mechanisms vary, depending on the type of data and where we process it. The information we encrypt includes your financial information, such as your personal information for KYC. Even before you log in to your account, the connection between your web browser and our platform has been encrypted using Transport Layer Security (TLS). TLS helps to ensure privacy for all communications between your computer and our servers. Because of TLS, you can feel confident that any information sent between you and us is kept private as it makes its way through the internet. We also use encryption when storing your personal information. The information we encrypt includes your financial information, such as Digital wallet address.
Our dedicated security team is always working for you
We have a dedicated in-house security team that works full-time to keep you safe. The team regularly reviews new code to minimize the potential for security issues, monitors our various tools and systems, and stays on top of industry trends and events. Keeping your account safe is our top priority, and we hope that gives you peace of mind. If you receive an email from our platform that you believe may be fraudulent, please forward the message to our Fraud Prevention Team: fraud@bfsinvestment.com. To report potential security vulnerabilities, please email: security@bfsinvestment.com For any other customer support, please contact our support team .
How Our Systems Work
We're Doing Our Part to Protect Your Account. BFS Investment has implemented a number of safeguards to help protect your account. These include:
Transaction Review
We monitor transactions on an automated and manual basis to detect potentially fraudulent and suspicious behavior on our customer accounts.
Automatic Logout
If you are logged in and inactive for an extended period of time, we'll automatically log you out of your account to protect you from unauthorized user access.
Contact Information Safeguards
Additional security mechanisms are in place to help protect you from unauthorized changes to your account information.
System Outage Protection
If there were ever a system outage, we have processes in place to help keep your financial account data safe and secure.
Responsible disclosure
BFS Investment values the disclosure of security vulnerabilities and will seek a coordinated approach to remediate any vulnerabilities disclosed responsibly.
BFS Investment operates a variety of information systems which we are responsible for safeguarding and where we welcome responsible disclosure reports.
To disclose a security issue affecting BFS Investment or our customers, please email us at security@bfsinvestment.com In your email, please include:
- • Your name
- • How can we contact you
- • Information to help identify the asset where you have identified a vulnerability A description of the issue
- • The steps to reproduce the issue
We will review and confirm any vulnerability reports and respond back to you in a timely manner. We may ask for additional information. While performing research to confirm a security vulnerability, please do not take any action that might harm BFS Investment, our employees, or our customers. Activities that are specifically prohibited include:
Any vulnerability testing that would cause a service outage (including denial of service, distributed denial of service, or other resource exhaustion attacks)
Any interaction with employees or customers (including but not limited to phishing or social engineering)
Intentionally accessing, processing, or transmitting identifiable customer information Exploiting vulnerabilities except for purposes of demonstration to BFS Investment personnel
FOR ENQUIRY
To assist you with your request, our agents are available online 24/7.
ADDRESS
199 WATER STREET 17TH FLOOR NEW YORK, NY 10038
EMAIL US
support@bfsinvestment.com
24/7 ACTIVE
Our Agents are always online.