Your account lives on your phone, which makes it convenient — and means the security of your money depends in part on how well protected that device is.
Most of what helps is a set of settings you adjust once and leave alone. They are listed roughly in order of how much difference they make. If you only have a few minutes, the first three are the ones worth doing.
The essentials
1. A screen lock, and a reasonably strong one
If your phone opens easily, the rest matters less.
Face or fingerprint unlock works well for everyday use.
A backup code of six digits or more is considerably harder to guess than a four-digit one.
Dates of birth and repeated or sequential digits are among the first combinations tried.
A short auto-lock delay limits how long an unlocked phone stays open.
Usually under Settings › Security on Android, or Settings › Face ID & Passcode on iPhone.
2. Keeping the operating system and apps updated
The least interesting item on the list and one of the most effective. Updates often close security gaps that are already being exploited, so software several months old may be missing fixes that are publicly known.
Turning on automatic updates means this happens without you thinking about it. If your phone no longer receives security updates from the manufacturer, that is worth factoring in when deciding whether to replace it.
3. Installing apps from official stores
Google Play and the App Store are the safer sources.
Installation files sent by message, email or link are worth declining, even from someone you know, since their account may not be under their control.
Checking the developer name helps, as fraudulent copies reuse the same app name and icon.
On Android, leaving installation from unknown sources switched off closes a common route.
Permissions
4. Accessibility permissions
Android's accessibility service exists so that people with disabilities can use their phones. It allows an app to read what is on screen, record what is typed, and interact with the interface on the user's behalf.
That combination is also what banking malware looks for. It does not need a password — it can wait until the account is opened normally and act from there.
It is worth reviewing which apps hold this permission, usually under Settings › Accessibility. Anything you do not clearly recognise is a reasonable candidate for removal; if a legitimate app needed it, it will ask again.
Worth knowing: a request to install an app and grant it accessibility permissions, made by someone who contacted you, is a common fraud pattern. We will not ask you to do this.
5. Other app permissions
An app requesting considerably more access than its function suggests is worth a second look. The most relevant permissions here are SMS, phone, contacts, microphone, camera, location, and display over other apps — the last of which allows one app to draw a screen on top of another.
Usually under Settings › Privacy on both platforms.
6. NFC
NFC lets you pay by holding your phone to a terminal. It is also involved in a technique that grew during 2026, in which someone is persuaded to install an app and then asked to hold their card against the phone to verify it — at which point the phone reads the card and relays the data elsewhere.
Turning NFC off when not paying reduces the exposure. There is no legitimate reason for anyone to ask you to hold your card against your phone to verify it.
What the app already does, and what you can adjust
7. Biometric unlock inside the app
As well as your phone's lock, the app has its own. Turning on face or fingerprint unlock for opening the app and confirming transactions means someone holding an unlocked phone still cannot move money.
8. Verifying your email address
Your phone number identifies your account, and verification codes are sent there by default. Codes can also go to your email address once it is verified.
Verifying it gives you an additional route to receive codes and regain access if you lose access to your phone number — through loss, theft or a problem with your mobile service. Useful to have in place before you need it.
9. One session at a time
Signing in on a new device closes any previous sessions, so only one is active at a time. If you ever think someone else has your account open, signing in yourself will close their session.
10. Signing in from a new phone
If you change phones, or sign in from a device we do not recognise, you will be asked to take a selfie. It takes a few seconds, and it has to be taken there and then — a saved photo or a screenshot will not pass. That is what stops someone who has your details from signing in on their own device. Good lighting, a clean and steady camera, and no glasses or hat generally make it work first time.
Worth knowing: we only ever ask for this inside the app, as part of signing in.
11. Your passcode and codes
Your passcode is best kept out of notes, photos and saved contacts.
Using a different passcode from the one on your phone and other apps limits the impact if one is exposed.
The six-digit code sent by SMS, WhatsApp or email is single-use and intended only for you. We will never ask you for it.
12. Screenshots
The money transfer and card detail screens are the ones most often targeted when someone is persuaded to share their screen. A request to screenshot them, or to share your screen while they are open, is worth treating with caution — there is no legitimate reason for anyone to need to see them.
When you are out
Public Wi-Fi. Open networks are worth avoiding for financial transactions; mobile data is generally safer. Turning off automatic connection to known networks avoids joining them without noticing.
Bluetooth. Leaving it off when unused is a small, easy reduction in exposure.
In public. Covering the screen when entering your passcode still helps — being observed over the shoulder remains a common way passcodes are learned.
Public USB chargers. Your own charger in a wall socket avoids the question. If you use an unfamiliar USB port, selecting "charge only" is the safer option.
If your phone is lost or stolen
Contact your mobile provider to report the line, since codes sent by SMS would otherwise continue to arrive on that number.
Sign in from another device, which closes the session on the lost phone.
Freeze your card in the app.
Change your passcode.
Contact us through the in-app chat, or email help@arqfinance.com from your registered address.
Erase the phone remotely if you have that set up.
Report the loss or theft to the relevant authorities.
Setting up remote location and erase in advance, and keeping your mobile provider's number somewhere other than your phone, makes this easier at the time.
A quick review
Screen lock with biometrics and a code of six digits or more
Automatic updates on
Apps installed only from official stores
Accessibility permissions reviewed
Other app permissions reviewed
NFC off when not in use
Biometric unlock on inside the app
Email address verified
Passcode not written down
Remote location and erase set up
The basics: we will never ask for your passcode, your verification codes or your full card details, and we do not provide support by phone or direct message. If you are unsure about a message, closing it and opening the app yourself is the most reliable check.
