Privacy & Security

Online Security Guarantee

Last updated:  May 29, 2026

Security Is a Shared Responsibility

Since 1999, millions of Canadians have trusted us with their investments. We take that seriously. At Questrade, we use industry-leading security tools and best-practices to keep your account protected.

The most reliable security comes from shared responsibility, though. By taking an active role in keeping your account safe, you make the measures we put in place even more effective.

If an unauthorized transaction occurs which is solely due to a breach to Questrade's systems, we will reimburse 100% of your direct financial loss1, subject to the terms of the guarantee. If a breach occurs because your personal credentials, devices, or email were compromised, the guarantee does not apply.

Together, our multiple layers of security and your diligence will help to keep your money safe.

What We Do to Keep You Safe


Encryption

We encrypt your data with secure 256-bit SSL while it's in transit between you and our systems. This encoding prevents third parties from reading or altering your information. All of our online applications use encryption to keep your connection secure.

Security tip: Always check your web browser's address bar to ensure that your connection is secure here.

2-Step Verification

Your account can only be accessed by providing the correct login credentials (your user ID and password) or through a Questrade API. When you verify your phone number and email in your Profile, you enable 2-step verification (2SV), which adds a layer of protection beyond your password.

With 2SV enabled:

  • We send you a time-sensitive verification request when you log in online or via your mobile device. Any new login attempt is blocked if the verification request is not successfully completed

  • We maintain a list of your trusted devices (the computers or devices you've designated for logging in to your account). When you log in from a trusted device, you're less likely to be asked for verification each time.

  • We also support mobile authenticator apps as an alternative way to verify your identity at login.

Learn more about Questrade's account security features.

Security tip: We will never ask you for your Questrade ID and password, and you should never share it with anyone else either. It's a good habit to change your password every 180 days (6 months).

Automated Alerts

Your account includes last login alerts so you can see when it was last accessed and from which device. If your account is accessed from a new device, you'll receive an automated email alert.

If you have a Questrade trading account, you can also set up confirmation alerts for all orders initiated from your account. These alerts confirm when orders are filled, and they serve as an early warning if activity occurs that you didn't initiate.

Security tip: You can also set up confirmation alerts for all orders from your account to re-confirm your actions.

Your Responsibility in Keeping Your Account Safe


These protections work best when you take an active role. It's our responsibility to keep our system secure. But if a breach occurs on your side, the guarantee may not apply.

Here's what you can do to stay safe:

Protect Your Credentials

  • Keep your user ID, password, and 2SV verification private. Do not share them with any person or organization, including online account aggregation services.

  • Change your password every 180 days (6 months).

  • Use a strong, unique password that you don't use for other accounts.

  • Verify your phone number and email in your Profile and/or set up a mobile authenticator app to enable 2SV.

If you think your account has been compromised: Act quickly. The sooner you respond, the more likely you are to limit any damage. Here's what to do:

  • Change your password immediately through the Questrade website or app.

  • To notify us, call us at 1-888-783-7866. Cooperate fully with Questrade and provide all information and take all actions that we reasonably request when investigating an alleged Unauthorized Transaction.

  • Review recent activity in your account, including orders, trades, and any changes to your security settings.

  • File a report with law enforcement. This is required to support any claim under the Online Security Guarantee.

If you discover an unauthorized transaction on your monthly account statement, you must notify us no later than six (6) days after receiving that statement.

Know What Questrade Will and Won't Ask For

Questrade employees will never call you and ask for your password, your 2SV verification, or your full account credentials. If you receive a call, email, or message asking for this information, it is not from Questrade. Do not respond. Instead, contact us directly.

Secure Your Devices and Connections

  • Maintain current versions of anti-virus and firewall software on any device you use to access your account.

  • Keep your device's operating system and software up to date.

  • Only access your Questrade account from a trusted device or network that you can reasonably consider secure.

  • Avoid connecting to public WiFi or unfamiliar networks while logged in to your account. Unsecured connections can expose your credentials without your knowledge.

Monitor Your Account

  • Review your account activity, statements, and trade confirmations at least monthly.

  • Pay attention to automated alerts as you receive them, including login notifications and order confirmations.

  • Sign out of your account and close your browser at the end of each session.

Notifying Us of Suspicious Activity

Notify us immediately upon discovering:

  • Your Account Credentials have become known to someone else; or

  • Any receipt by you of an Automated Alert that you do not recognize (such as a confirmation of an order that you did not place, or of an access authorization of a third party application)

Notify us immediately, or in any event no later than 6 days after the date you receive your electronic monthly account statement upon discovering an Unauthorized Transaction occurred in your account.

To notify us, call us at 1-888-783-7866. Cooperate fully with Questrade and provide all information and take all actions that we reasonably request when investigating an alleged Unauthorized Transaction.

The Online Security Guarantee's Coverage


What's Covered

If an unauthorized transaction in your account occurred as a result of a breach of Questrade's systems2 and you suffered a direct financial loss, Questrade will reimburse 100% of your direct loss. This reimbursement is conditional on your adherence to the responsibilities and conditions outlined on this page.

What's Not Covered

The guarantee covers breaches of Questrade's systems. It does not cover losses that result from a breach on your side. Common examples include:

  • Your personal email is compromised and used to access or reset your Questrade credentials

  • You enter your login information on a fraudulent site after clicking a phishing link

You share your credentials, directly or indirectly3, with another person or service

What Qualifies as an Unauthorized Transaction

An Unauthorized Transaction means a transaction carried out in your Questrade account without your permission, authorization, or knowledge, and where a law enforcement report provides supporting information that you have been a victim of fraud.

An unauthorized transaction does not include any transaction carried out by:

  • A person acting under authority to trade in your account

  • A person acting on your behalf

  • A person to whom you, directly or indirectly, provided your account credentials (your account number, user ID, 2SV/mobile authenticator verification, and/or password)

  • You or another person acting on your behalf using a third-party API, whether the API has been authorized by Questrade or not

Conditions for Reimbursement

Questrade will reimburse 100% of your direct financial loss from an unauthorized transaction provided that all of the following are true:

  • The unauthorized transaction occurred as a result of a breach to Questrade's systems.

  • You did not share your account credentials with any other person4 or organization, including online account aggregation services, and were not otherwise negligent or careless in keeping your credentials confidential.

  • You did not engage in any fraudulent, criminal, or dishonest activity with respect to your account(s), alone or in concert with others, and you complied with all contractual obligations you have with Questrade.

  • You took reasonable steps to protect your account credentials, including verifying your phone and email in your Profile and/or setting up a mobile authenticator app to enable 2SV, before the unauthorized transaction occurred.

  • You regularly reviewed your account activity, statements, and trade confirmations (at least monthly).

  • You maintained current versions of anti-virus and firewall software.

  • You notified law enforcement of the unauthorized transaction upon discovery.

  • You only accessed your Questrade account from a trusted device or network that would reasonably be deemed secure, and did not use a device that was unpatched or that would reasonably be believed to contain software capable of compromising your account credentials.

  • You took reasonable precautions to prevent unauthorized transactions, including signing out of your account and closing your browser at the end of each session, and not accessing your account through an unsecured internet connection.

Limitations

Questrade will not be liable to you for any indirect, consequential, special, aggravated, punitive, or exemplary damages whatsoever, in whole or in part (including but not limited to any business interruption, loss of profit, loss of opportunity, market loss, or any other commercial or economic loss) resulting from an unauthorized transaction in your account, even if we have been advised of the possibility of such damages.

Where Questrade reimburses you under this Guarantee, you assign to Questrade, up to the amount reimbursed, your rights of recovery against any person responsible for the unauthorized transaction, and you will not recover the same loss more than once.

We may amend the terms and conditions of, or revoke, this Online Security Guarantee at any time without notice.

At Questrade, your security is very important to us. Thank you for your efforts to secure your account information and helping us to ensure the safety of your information.


1 Direct financial loss means the value of cash or securities removed from your account in the unauthorized transaction, measured as at the time of the transaction; it does not include later market movement, fees, or any indirect or consequential loss

2 Breach of Questrade's systems means unauthorized access to or compromise of the information systems Questrade operates or controls; it does not include compromise originating from your credentials, devices, email, or networks.

3 Indirectly providing your Questrade credentials can occur in a variety of ways. For example, it can occur without your knowledge as a result of accessing public WiFi hotspots while using your mobile device to access your Questrade account or by logging into your Questrade account or another account which you have set up to link to your Questrade account on a public computer or public WiFi hotspots, or other WiFi networks that you are unfamiliar with or have reason to distrust.

4 With the exception of your Authorized Traders that you have designated by both you and the Trader signing the Trading Authorization form.