Trust & legal

Security and data

Version 2026-10-v1 Effective 6 October 2026 Hosted in India

1 In transit and at rest

Every connection to fxlayerhq.com uses TLS. Data at rest is encrypted by Google Cloud, in the Mumbai region. Passwords are stored as hashes; authenticator secrets and the credentials you connect — ERP, bank, your own mailbox — are encrypted before they are stored and are never displayed back in full. Pages that carry your data are served with no-store headers, so a shared browser does not keep them.

2 Who can get in

Two-factor sign-in with an authenticator app is offered during the free trial and required for every member once the workspace is on a paid plan; repeated failed attempts lock the account, and signing a document asks for a fresh code. Roles — owner, compliance, operator, viewer — limit what each member can see and change. A partner you invite reaches only the pages you allow, and administrators of the platform see money and status, never your transactions.

3 Audit trail and retention

Every create, edit, match, cancellation, signature and closure carries the person who did it and when. Closed records show their eight-year retention date, and every e-signed document carries a public verification code anyone can check. The register saves only what changed, and refuses to overwrite a newer change made by a colleague.

4 Your copy, any time

Export every register as Excel from My Account › Data & connections, download a closed transaction with all its attachments, or ask for a complete wipe of every transaction and attachment. Nothing is written back to your ERP.

5 Reporting a security problem

Found a vulnerability or something that looks wrong? Write to hello@fxlayerhq.com with "Security" in the subject. We acknowledge within two working days and keep you informed until it is fixed. Please do not test against other customers' data.