Skip to content

Regulation, security, and fraud prevention

An operational path for checking intermediaries and platforms, understanding the protections that apply, recognising warning signs, and responding without treating an indicator as a verdict.

When you entrust someone with money, data, or orders, the first question is not “Do they look trustworthy?” It is: which legal entity provides which service, under which permission, in which country, and under which contract?

In plain terms — A polished website, a familiar brand, or a name found in a register is not enough. The entity, service, contact details, protections, and current status must all match.

Rules and safety: five steps A five-check path for assessing an intermediary and responding to critical inconsistencies. Rules and safety: five steps Identity, permissions, assets, conduct, and response need different evidence Counterparty: Identify the legal entity entering the relationship. A brand, website, or app does not replace an official register. 1 · IDENTITY Counterparty Legal entity official register OPEN THIS STEP Service: Check that the permission covers the actual service. Registration for one activity does not authorise every other activity. 2 · PERMISSION Service Specific activity authorised scope OPEN THIS STEP Custody: Trace who holds cash and instruments, how they are recorded, and what happens during a crisis. 3 · ASSETS Custody Title + records segregation + access OPEN THIS STEP Continuity: Monitor costs, conflicts, service quality, withdrawals, communications, and operational continuity over time. 4 · CONDUCT Continuity Costs + conflicts complaints + operations OPEN THIS STEP Stop: When critical inconsistencies emerge, stop payments and access, preserve evidence, and use independently sourced official contacts. 5 · RESPONSE Stop Send nothing else evidence + official routes OPEN THIS STEP A licence does not guarantee returns, solvency, or full recovery Cyclepedia diagram · Emiciclo
The path separates regulatory verification, operational protection, and the response to suspected fraud.
Select the highlighted points to explore the detail

Three different questions

Regulation means identifying the rules that apply to a person, service, product, and jurisdiction. A licence is not universal: it may cover some activities but not others.

Security means understanding how access, money, instruments, keys, orders, records, and continuity are managed. An authorised firm still carries operational, financial, and market risks.

Fraud prevention means recognising inconsistencies and deceptive conduct before sending funds or data. A red flag calls for a check; by itself, it is not proof that anyone has committed an offence.


The protection path

1. Identify the counterparty

Find the legal name, registered office, registration number, and competent authority in the contractual documents. The app name or domain may be only a brand. Exchange, broker, dealer, and custodian explains how to separate the roles.

2. Verify the service and permission

Open the register from the authority's official website, find the entity, and check its status, permitted activities, restrictions, and contact details. Do not use a link received in a chat or advert: clone websites copy logos and licence numbers too. The full procedure is in Due diligence.

3. Understand where the assets are

Ask who holds the cash and instruments, how they are recorded, which sub-custodians are involved, and what the contract says about transfers, insolvency, or disruption. Segregation, custody, and compensation arrangements address different risks; none guarantees returns or complete recovery. See Client asset protection.

4. Check conduct and continuity

Costs, risks, conflicts, execution policy, withdrawals, complaints, and communications should be consistent with the stated service. Compliance explains how obligations, controls, and evidence connect without confusing them with a trader's personal discipline.

5. Stop when critical details do not match

Stop and verify through an independent channel if a contact differs from the register, money must be sent to an individual, or someone asks for a seed phrase, remote access to a device, or another payment to “release” a withdrawal. Red flags distinguishes contextual signals from signals that require an operational stop.


If you suspect fraud

Do not send more money or follow instructions from the same channel. Preserve URLs, messages, receipts, addresses, and transaction history; contact the intermediary, bank, or provider through verified details; and consult the authority responsible for the relevant country and service. If credentials or keys may be compromised, secure access from a trusted device.

Be wary of anyone promising certain recovery in exchange for an advance fee: a recovery scam often targets someone who has already suffered a loss. Reporting procedures, deadlines, and channels vary by jurisdiction; this page is not a substitute for legal or operational assistance.


Fraud patterns with dedicated entries

The most common patterns have their own pages: fake broker, clone website, fake exchange, phishing, wallet drainer, seed phrase theft, signal group scam, fake trading bot, pig butchering, fake prop firm, Ponzi scheme, guaranteed returns, romance scam, and social engineering.


Sources

Sources and register status checked on 18 August 2026. Authorisations, warnings, and complaint channels can change: check them again on the date of the transaction.


  1. Due diligence
  2. Client asset protection
  3. Compliance
  4. Market abuse and manipulation
  5. Red flags
  6. Broker risk