Account, Access and Security

What stays under your control.

Chilla can do real work without owning your money or needing your provider password. Your account remains yours.

Article type: Concept + Reference Last reviewed: October 3, 2026

Plain-language summary

  • Beaverly does not hold your market funds.
  • Connecting a trading account does not by itself activate live work.
  • You review the PLAN and complete the required activation step before Chilla carries live financial work.
  • Chilla works inside the boundaries you authorize.
  • Passwords, OTP/MFA, identity checks, legal declarations and money-moving confirmations stay with you.
  • Chilla does not store plaintext broker passwords.

Your Beaverly account

Use your Beaverly account credentials only on official Beaverly/Chilla surfaces. Keep your password unique, protect access to your device, and use the account-security controls available in Chilla if you need to change your email or password.

Provider credentials

Your provider login is different from your Beaverly login. When a supported provider journey reaches a sensitive credential step, you take over that step yourself.

  • Do not paste broker passwords into chat.
  • Do not send OTPs, MFA codes or recovery codes to Chilla or Beaverly support.
  • When you take over a sensitive credential step, Chilla does not observe that credential-entry activity.
  • Chilla does not store plaintext broker passwords.

Retained provider sessions

Where product policy allows a provider session to be retained so supported assistance can continue later, that session is protected with encryption at rest and in transit and kept isolated.

You should still treat the trading account as sensitive and revoke or reconnect access when you believe the account, device or session may be compromised.

Sensitive actions stay yours

Chilla can help

Use the web to navigate supported trading-account setup and ordinary account-management journeys, explain what you are looking at, and get you to the right area.

You decide and confirm

Identity/KYC, legal declarations, OAuth approval, transaction details, source/destination choices, deposits, withdrawals, transfers and other consequential confirmations.

Authorization for live work

Talking to Chilla or connecting a trading account does not silently authorize live financial work. You make the material choices that belong to you, then Chilla presents the exact PLAN for review.

Approving the PLAN moves you to the required disclosure. Activate is the final action that puts that reviewed work live. Chilla can then carry ongoing activity inside the authorized scope. A material change that needs new authority comes back to you.

If something looks wrong

  • Pause or stop active work if it no longer matches your intent.
  • Ask Chilla what happened and ask Chilla to report back with more detail.
  • Disconnect or revoke provider access when appropriate.
  • Contact Beaverly support without sending passwords, OTPs or other secrets.