Fetching the page
Fetching the page
Online security
This page makes two kinds of statement: what this website does, each with the way to confirm it yourself, and general guidance for looking after your own accounts. It makes no claim that cannot be tested.
This website
These describe the public website you are reading. They are not statements about trading platforms, client portals or internal systems, which are separate and are not covered here.
Every page is served over an encrypted connection, and the site instructs browsers to refuse an unencrypted one.
How to checkThe address bar shows https://. In your browser’s developer tools, the response carries a Strict-Transport-Security header.
The Content-Security-Policy allows scripts from this website’s own origin and from nowhere else. Inline scripts are permitted because the framework needs them to start a statically generated page.
How to checkRead the Content-Security-Policy response header: script-src lists only ‘self’. The Network panel shows no script loaded from another domain.
There are no advertising tags, tracking pixels or third-party analytics scripts on these pages, and no advertising or analytics cookies. The site counts its own page views as daily totals: one request to its own address per page, carrying the page’s path and one word for where you came from, with no cookie and no identifier. You can switch it off in your preferences, and a Global Privacy Control or Do Not Track signal is honoured.
How to checkOpen the Network panel and reload: the only counting request is one POST to /api/pulse on this site, and its body shows the two fields. Open the storage panel and look at the cookies for this site.
A form on this site submits to this website’s own endpoint. The policy forbids a form from posting anywhere else.
How to checkThe Content-Security-Policy header contains form-action ‘self’. Submit a form with the Network panel open and read the request address.
Theme, density, time zone and similar choices are kept in your browser’s local storage. They are not sent to a server.
How to checkThe Cookie & Storage Notice lists every key. The preferences page shows and clears them.
If you switch it on in your preferences, a service worker supplied by this website keeps the calculators and the pages you have opened in your browser’s cache storage, so they open without a connection. It is off by default. It is this site’s own script. It answers only requests for this site’s public pages and static files, never the staff console, a form or another site, and it sends nothing anywhere.
How to checkIn your browser’s developer tools, the Application or Storage panel lists the service worker (sw.js) and its caches, each named gx-…. The preferences page removes them and switches the copy off.
Market charts, the economic calendar, heat maps and quote panels from TradingView are embedded frames. Each loads when you ask for it, or as it scrolls into view if you have switched that on in your preferences. No TradingView script runs on these pages, no other site may be framed, and this site may not be framed by anyone.
How to checkThe header lists TradingView under frame-src and sets frame-ancestors to ‘none’.
The site’s Permissions-Policy switches these browser features off for every page.
How to checkRead the Permissions-Policy response header.
Network requests made by these pages are limited to this website’s own origin and, where one is configured, GIO4X’s own hosted database project. The full list of what is stored in your browser is in the Cookie & Storage Notice.
Your side
General guidance, written for anyone with an online financial account. It is not specific to GIO4X and does not depend on it.
What is not claimed
The previous GIO4X websites described encryption strengths, firewalls, fraud-detection systems, audits and insurance. None of those statements came with evidence a visitor could examine, so none of them is repeated here.
If GIO4X later publishes an independent assessment, it will appear in the transparency table with the name of the assessor, the scope and the date. Until then the honest position is the one on this page: here is what the website does, and here is how to see it.
Reporting
A security.txt file and a dedicated security contact will be published once GIO4X has confirmed them. They are not published yet, and no address is given here that has not been confirmed.
Until then, use the contact page and choose the Security topic, or write to info@gio4x.com. Describe what you found and how to reproduce it. Please do not include passwords, one-time codes or other people’s personal data.
Page last changed: