Vertex Capital & Tech Limited — Trading as Vorum Capital
1. INTRODUCTION
1.1 Purpose
This Fraud Prevention Policy ("Policy") establishes the framework by which Vertex Capital & Tech Limited ("the Company"), trading as Vorum Capital, identifies, prevents, detects, investigates, and responds to fraud affecting the Company, its clients, or its payment processing partners.
Fraud prevention is integral to the Company's risk management framework and operates in conjunction with the AML/KYC Policy, Complaints Handling Procedure, and applicable Saint Lucia legislation, including the Proceeds of Crime Act No. 9 of 2010 and the Money Laundering (Prevention) Act, Cap. 3.08.
This Policy applies to all Company personnel, agents, Introducing Brokers, and third-party service providers acting on the Company's behalf.
1.2 Scope of Fraud
For the purposes of this Policy, fraud includes but is not limited to:
- Identity fraud: Use of false or stolen identity documents to open a trading account;
- Payment fraud: Use of stolen credit/debit cards, hijacked bank accounts, or unauthorized payment instruments to fund a trading account;
- Chargeback fraud (friendly fraud): Deliberate initiation of a payment dispute by a client after genuinely engaging in trading, with the intent to recover funds not legitimately entitled to be recovered;
- Account takeover: Unauthorized access to a legitimate client's account by a third party;
- Multiple account fraud: Operation of multiple trading accounts by the same individual or coordinated group, in violation of the Company's one-account policy, for the purpose of abusing bonuses, exploiting platform arbitrage, or concealing identity;
- Bonus abuse: Systematic exploitation of promotional offers through coordinated account activity, hedged positions across multiple accounts, or other manipulative techniques;
- Round-tripping / pass-through: Use of trading accounts primarily as a vehicle for moving funds rather than for genuine trading activity (related to AML typologies);
- Chargebacks for trading losses: Filing payment disputes in respect of genuine trading losses, misrepresenting them as unauthorized transactions;
- Affiliate / IB fraud: Introducing Brokers or affiliates generating fake referrals, self-referrals, or coordinating fraudulent account activity to generate commissions.
2. FRAUD RISK ASSESSMENT
2.1 Fraud Risk Profile
The Company's business model — fully online, international client base, leveraged financial products, multiple payment methods including digital assets — carries an elevated inherent fraud risk relative to traditional financial services. The key fraud risk vectors are:
| Risk Vector | Inherent Risk | Primary Control |
|---|---|---|
| Identity fraud at onboarding | High | KYC document verification + liveness check |
| Payment fraud (stolen cards/accounts) | High | Card authentication + same-source withdrawal |
| Chargeback fraud | High | KYC before deposit + transaction documentation |
| Account takeover | Medium | 2FA + session monitoring + geolocation alerts |
| Multiple accounts | Medium | Device fingerprinting + IP monitoring |
| Affiliate fraud | Medium | IB monitoring + referral pattern analysis |
| Round-tripping / AML overlap | High | Transaction monitoring (see AML/KYC Policy) |
2.2 Fraud Risk Review
The fraud risk assessment is reviewed at least annually by the Compliance Officer and updated following any material incident, change in payment methods, or emerging fraud typology identified in industry reports.
3. FRAUD PREVENTION CONTROLS
3.1 Pre-Onboarding Controls (Identity Verification)
The first and most important fraud prevention control is the Company's KYC process. No client account is activated and no deposit is credited to a trading account until the following are verified:
(a) Government-issued photo identification: The document is checked for:
- Authenticity indicators (security features, MRZ validity);
- Signs of digital manipulation or tampering;
- Consistency between document details and registration information;
(b) Proof of residential address: Verified for:
- Consistency with the registered address;
- Age within the acceptable limit;
- Authenticity (not digitally altered);
(c) Liveness check and selfie: Verified for:
- Biometric consistency between the selfie and the ID photograph;
- Signs of "presentation attacks" (photo of a photo, mask, or digital overlay);
(d) Sanctions and PEP screening: Client name checked against applicable lists before account activation.
Full KYC procedures are described in the AML/KYC Policy (Part III).
3.2 Payment-Level Controls
(a) Prohibition on third-party deposits:
All deposits must come from a payment instrument registered in the account holder's name. Third-party deposits are identified through:
- Name matching between the payment instrument holder and the registered account holder;
- Where available, bank account holder name verification via the payment processor;
- IP address and geolocation correlation.
Third-party deposits, when detected, are returned to the source without processing and the account is flagged for enhanced monitoring.
(b) Card authentication:
Credit and debit card transactions are subject to:
- 3D Secure (3DS v2) authentication where supported by the issuing bank and payment processor;
- BIN (Bank Identification Number) analysis to detect high-risk card categories;
- Card velocity checks (multiple card attempts in a short period);
- Country-of-issue consistency check against the client's registered jurisdiction.
(c) Digital wallet and cryptocurrency deposit controls:
- Cryptocurrency deposits are subject to blockchain analytics screening where technically feasible;
- Deposits from mixers, tumblers, or other obfuscation services are prohibited;
- Wallet addresses may be screened against sanctions and high-risk blockchain address databases;
- USDT and other stablecoin deposits are converted at the prevailing rate upon receipt.
(d) PIX (Brazil-specific):
- PIX transactions must originate from a CPF (individual) or CNPJ (corporate) registered to the account holder;
- CPF/CNPJ provided by the client must match the PIX key holder's registration.
3.3 Transaction-Level Controls
(a) Velocity limits:
The Company applies transaction velocity limits including:
- Maximum single deposit amount by payment method (published in the Client Portal);
- Maximum 24-hour deposit volume for new accounts (pre-full KYC verification);
- Deposit velocity alerts triggered by volume inconsistent with client profile.
(b) Device fingerprinting:
The Company's systems record device characteristics (browser, operating system, screen resolution, fonts, plugins) to create a device fingerprint for each client session. Multiple accounts accessed from the same device are flagged for review.
(c) IP address monitoring:
- Geolocation is checked for consistency with the client's registered address;
- VPN and proxy usage is detected and logged;
- Multiple accounts accessing from the same IP address are flagged;
- IP addresses from high-risk jurisdictions trigger enhanced monitoring.
(d) Behavioral analytics:
Account activity is monitored for behavioral anomalies, including:
- Sudden change in login location;
- Login at unusual hours inconsistent with the client's historical pattern;
- Rapid succession of withdrawal requests following a deposit;
- Large position sizes inconsistent with the client's historical profile.
3.4 Withdrawal Controls
All withdrawal requests are subject to:
(a) Same-source policy:
Withdrawals are processed to the same payment method used for the original deposit wherever technically possible. Requests to withdraw to a different account require enhanced verification and CO review.
(b) Withdrawal verification:
Withdrawals above USD 5,000 require additional verification, including re-confirmation of identity where the account was last KYC-verified more than 12 months ago.
(c) Withdrawal processing timelines:
- Withdrawals up to USD 5,000: 1–5 business days after approval;
- Withdrawals above USD 5,000: up to 21 business days after approval.
The longer processing timeline for large withdrawals allows time for enhanced review, potential fraud pattern identification, and coordination with payment processors.
(d) Third-party withdrawal prohibition:
Withdrawals to accounts not in the client's name are never processed. Requests for third-party withdrawals are flagged as a fraud indicator and reviewed by the CO.
(e) Chargeback risk hold:
Following a card deposit, the Company may apply a minimum trading period or holding period before processing a withdrawal to the same card, in order to reduce chargeback exposure. This period and the applicable conditions are disclosed during the withdrawal process.
4. CHARGEBACK PREVENTION AND MANAGEMENT
4.1 Chargeback Prevention Strategy
The Company operates a proactive chargeback prevention strategy based on:
(a) Robust KYC before first deposit: No card transaction is processed for an account that has not completed at least minimum identity verification;
(b) Explicit transaction consent: Clients must actively accept the Terms and Conditions, Risk Disclosure, and this Policy before their first deposit is processed. The acceptance is recorded with timestamp and IP address;
(c) Deposit confirmation communications: All deposits trigger an automated confirmation email to the registered address, with transaction details;
(d) Transparent trading records: Full audit trail of all deposits, trades, P&L, fees, and withdrawals, available to the client through the Client Portal at all times;
(e) 3DS authentication: Significantly reduces card-not-present fraud and strengthens the Company's position in dispute proceedings;
(f) Client-facing resolution: Clients are encouraged to contact the Company before initiating any dispute with their bank or card provider. The Company's complaint handling team is specifically resourced to resolve potential chargeback situations before they escalate.
4.2 Chargeback Response
In the event that a chargeback or payment dispute is received by the Company through a payment processor or acquiring bank, the Company will:
(a) Identify the relevant client account and place a hold on any pending withdrawals pending resolution;
(b) Compile the chargeback response pack within the timeframe required by the relevant card scheme or payment network. The response pack includes:
- Copy of the signed (electronic) Client Agreement;
- KYC verification records and timestamps;
- IP address logs for account registration and the disputed transaction;
- Screenshot evidence of T&C acceptance with timestamp;
- Complete trading history showing the client actively traded;
- Deposit confirmation email records;
- Any prior communication from the client acknowledging the transaction.
(c) Submit the response pack to the payment processor or acquiring bank within the required timeframe;
(d) Record the chargeback in the Chargeback Register with outcome tracking.
4.3 Chargeback Register
The Company maintains a Chargeback Register that records:
- Date chargeback received;
- Client account number;
- Amount disputed;
- Payment method and card scheme;
- Reason code;
- Response submitted (Y/N) and date;
- Outcome (won / lost / partial);
- Lessons learned.
The Chargeback Register is reviewed monthly by the Compliance Officer to identify patterns, high-risk payment methods, and potential systemic issues.
5. ACCOUNT TAKEOVER PREVENTION
5.1 Authentication Controls
Client accounts are protected by:
- Email address and password authentication (minimum password requirements enforced);
- Two-factor authentication (2FA) via authenticator app or SMS (strongly recommended; may be made mandatory for high-value accounts);
- Session timeout after a period of inactivity;
- Single active session enforcement (new login terminates existing session with notification to the client).
5.2 Suspicious Login Detection
The following events trigger a security alert and temporary account restriction pending client verification:
- Login from a new device or browser;
- Login from a geographic location significantly different from the client's registered address or prior login history;
- Multiple failed login attempts;
- Simultaneous login attempts from different geographic locations.
5.3 Withdrawal Security
In addition to standard withdrawal processing, the Company applies:
- Email verification for withdrawal requests above a defined threshold;
- A holding period between a password change and the ability to process a new withdrawal (to protect against account takeover leading to immediate fund diversion).
6. FRAUD RESPONSE PROCEDURE
6.1 Detection to Response
Upon detection or reasonable suspicion of fraud:
| Step | Action | Timeframe |
|---|---|---|
| 1 | Account suspended; all pending transactions placed on hold | Immediately |
| 2 | Compliance Officer notified with full case details | Within 1 hour |
| 3 | CO reviews and determines whether to initiate full fraud investigation | Within 4 hours |
| 4 | Full investigation commenced; evidence preserved and documented | Within 24 hours of CO determination |
| 5 | Client contacted for explanation (where appropriate and where doing so does not compromise the investigation) | Within 2 business days |
| 6 | CO issues investigation conclusion | Within 5 business days for standard cases; up to 15 business days for complex cases |
| 7 | Where fraud confirmed: account permanently closed; funds frozen; STR filed with FIA if AML nexus; law enforcement notified where appropriate | Upon confirmation |
| 8 | Payment processor notified to prevent further exposure | Upon confirmation of fraud |
| 9 | Lessons learned documented; controls updated if required | Within 30 days of case closure |
6.2 Evidence Preservation
From the moment fraud is suspected, all relevant data is preserved and must not be altered or deleted:
- Account records, login logs, IP addresses, device fingerprints;
- All communications (emails, support chats, phone call recordings);
- Transaction records, screenshots, and system audit trails;
- KYC documents submitted by the suspected fraudster.
Evidence is preserved in accordance with applicable data protection requirements and in a format suitable for production to law enforcement or courts.
6.3 Law Enforcement Cooperation
The Company will cooperate fully with law enforcement agencies investigating fraud. This includes:
- Providing account information and transaction records pursuant to valid legal process;
- Providing evidence to support prosecutions;
- Filing reports with the Financial Intelligence Authority (FIA) of Saint Lucia where the fraud has an AML/CFT dimension.
The Company will not tip off suspected fraudsters that they are under investigation.
7. STAFF TRAINING
All personnel with client-facing, payment processing, or compliance responsibilities receive:
- Fraud awareness training at induction;
- Annual fraud prevention refresher training;
- Ad hoc training on emerging fraud typologies as they are identified.
Training completion is documented and retained for 5 years.
8. REVIEW
This Policy is reviewed annually by the Compliance Officer and approved by the Board. Reviews are triggered earlier following:
- A material fraud incident;
- A significant change in payment methods or product offerings;
- Changes in the fraud risk landscape (new typologies, regulatory guidance);
- A material increase in chargeback rates.
