Account protection
Investor diligence should cover authentication, session controls, recovery, and suspicious activity paths.
Security messaging for investors should cover account protection, wallet boundaries, payment posture, support controls, and responsible-play systems without pretending public copy is a security audit.
Signup currently requires a referral code, and email verification is required before deposit or play.
The app support center documents authenticator-app and email-based two-factor flows.
Users can view active sessions and revoke other sessions from account settings.
Frozen account support copy targets review in one to two days.
Investors should understand what Flux protects, what partners provide, and what evidence can be shared privately.
Security should feel like an operating system, not a badge row.
The public site should make clear that final policies, audits, and production controls belong in formal diligence.
Avoid claims that imply a completed audit unless that audit exists and is approved for public disclosure.
Investor diligence should cover authentication, session controls, recovery, and suspicious activity paths.
USDC rails, wallet providers, on-ramp partners, and reconciliation should be explained with precision.
The fairness system should be treated as security-critical product infrastructure.
Limits, eligibility, and support escalation are part of operational readiness.
Security is framed as account control, wallet boundary, fraud monitoring, and escalation readiness.