Security
How we protect your Polar Zinsmere account
Account security is not a single feature, it's a set of layered controls working together. Below is exactly what protects your account, your data and your funds, point by point.
1. Two-factor authentication (2FA/MFA)
Every account can enable an authenticator-app code or an SMS one-time code as a second step at login, in addition to your password. We strongly recommend enabling 2FA immediately after registration, since it is the single control most likely to stop an account takeover even if your password is compromised elsewhere. 2FA is optional at signup but can be made mandatory on request for accounts holding larger balances. If you lose access to your authenticator device, recovery requires verifying your identity through our support team using the same documents accepted during onboarding, never by email alone.
We support authenticator apps over SMS codes wherever possible, since SMS can be vulnerable to SIM-swap attacks in a way an authenticator app installed on your device is not. If you change phones, re-enrolling 2FA takes a few minutes from your account settings; do it before your old device is wiped or handed over, not after.
2. Encryption
Data is encrypted both in transit and at rest. Every connection between your browser and our servers uses TLS encryption, so information can't be read if intercepted on the network. Stored account data, including identity documents submitted for verification, is encrypted at rest on our infrastructure. Encryption keys are managed separately from the systems that use them, and access to decrypted data is limited to the specific services that need it to function, such as identity verification and account support.
We periodically review our encryption standards against current industry practice and rotate keys on a defined schedule rather than leaving them static indefinitely. Backups of account data follow the same encryption standard as live systems, so a backup is never a weaker link in the chain than the production environment it's copied from.
3. Protection against fraud and phishing
All official communication comes only from our verified domain and support email address, never from a look-alike domain or a personal account. We publish our official channels on the Fraud Warning page so you can check any message that claims to be from us. We never ask for your password, full 2FA seed, or a one-time code over the phone or by email, and any message that does should be treated as fraudulent and reported to [email protected] immediately.
We also actively monitor for look-alike domains and impersonation attempts using our brand, and act to have fraudulent sites and profiles taken down when we identify them. If you're ever unsure whether a message, call or website is genuinely from Polar Zinsmere, don't click through, contact us directly through the channel listed on this site instead.
4. Login notifications
We send an email alert whenever your account is accessed from a new device, a new browser, or an unusual location. If activity on the notification looks unfamiliar, you can secure your account directly from the alert by forcing a password reset and reviewing active sessions. These alerts are not optional and cannot be turned off, since they're one of the fastest ways for you to catch unauthorised access before any damage is done.
Alerts include enough detail, approximate location and device type, to let you judge in seconds whether the login was actually you. If you don't recognise a login, act on it immediately rather than waiting to see if anything else looks wrong; the alert itself is designed to give you time to lock the account down before further access occurs.
5. Device and session management
Your account dashboard shows every currently active session, including the device type, approximate location and the time it was last active. You can revoke any session remotely with a single click, which immediately signs that device out. Sessions also expire automatically after a period of inactivity, so a forgotten logged-in browser on a shared computer doesn't stay open indefinitely.
We recommend reviewing your active sessions periodically, not just when something feels wrong, so an unfamiliar entry stands out immediately rather than blending into a list you never check. Revoking a session you don't recognise takes one click and doesn't affect any of your other active devices.
6. Account recovery
If you lose access to your account, recovery always requires identity verification, using the same type of documents you provided when you registered, matched against the details on file. This is deliberately slower than a simple email link because it prevents someone else from taking over your account by compromising only your inbox. Recovery requests are handled by our support team directly and typically resolved within a few business days once documents are received.
We understand the friction this adds when you genuinely need fast access back to your account, and we've kept the process as quick as we can without weakening it. Keeping your contact details and identity documents up to date in advance is the single biggest thing you can do to speed up a future recovery request.
7. API key permissions
If you connect an external exchange account, the API key you generate should be scoped to the minimum permissions the platform actually needs: market data and trading. We never require withdrawal permission on any API key you connect, and we recommend you never grant it. Restricting API scope this way means that even if a key were ever exposed, funds could not be moved off the connected exchange through it.
Most major exchanges let you set an IP allow-list on a key as an additional layer, restricting it to only accept requests from our systems. It's an optional extra step, but a worthwhile one if the exchange you're connecting supports it, and your manager can help you find the setting if you're not sure where it is.
8. Audit history
Every login, connection change, and strategy or settings update on your account is logged with a timestamp and visible to you in your account history. This gives you a full record you can review at any time, and it's the same log our support and compliance teams use if you ever report suspicious activity, so nothing has to be reconstructed from memory.
The audit log is append-only, meaning past entries can't be edited or deleted, by you, by us, or by anyone else, once they're recorded. That's a deliberate design choice: it means the log is trustworthy as evidence if you ever need to dispute activity on your account.
9. Incident support
If you believe your account has been compromised, contact [email protected] immediately and we can suspend account activity while we investigate. Our support team will confirm your identity, walk through the audit history with you, and reset credentials as needed. Confirmed incidents are escalated internally to our compliance team, and we will communicate with you throughout the process rather than leaving you waiting on an update.
Once your account is secured, we'll go through the audit log with you to confirm exactly what happened and when, and help you review whether any connected exchange keys also need to be rotated as a precaution. Reporting an incident quickly, even if you're not fully sure something is wrong, is always the right call.