XM does not provide services to residents of the United States of America.

This website is operated by Trading Point of Financial Instruments Pty Ltd

  • MEMBER LOGIN
  • HELP CENTER
  • OPEN AN ACCOUNT
    • English
XM Logo
    XM Logo
    • Home
    • Trading
      Trading

      At XM we offer both Micro and Standard Accounts that can match the needs of novice and experienced traders with flexible trading conditions and leverage up to 30:1.

      We offer a range of over 50 currency pairs, precious metals, energies and equity indices.

      Risk Warning: Trading on margin products involves a high level of risk.

      Accounts
      • Trading Account Types
      Instruments
      • Forex Trading
      • Stocks
      • Commodities
      • Equity Indices
      • Precious Metals
      • Energies
      Trading Conditions
      • Execution Policy
      • Spreads
      • Overnight Positions
      • Trading Hours

      Access the global markets instantly with the XM MT4 or MT5 trading platforms.

      Open an Account
    • PLATFORMS
      PLATFORMS

      Start trading the instruments of your choice on the XM MT4 and MT5, available for both PC and MAC. Alternatively, you may also want to try out the XM WebTrader, instantly accessible from your browser.

      In addition, our fully-fledged platforms for mobile devices compatible with both MT4 and MT5 make it easy to access and trade on your account from your smartphone or tablet. You can choose your favorite mobile or desktop platform from the list.

      Risk Warning: Trading on margin products involves a high level of risk.

      PC / MAC
      • MT4 for PC
      • MT4 for Mac
      • MT4 WebTrader
      • MT5 for PC
      • MT5 for Mac
      • MT5 WebTrader
      Smartphones
      • MT4 for iPhone
      • MT4 for Android
      • MT5 for iPhone
      • MT5 for Android
      Tablet
      • MT4 for iPad
      • MT4 for Android
      • MT5 for iPad
      • MT5 for Android

      Access the global markets instantly with the XM MT4 or MT5 trading platforms.

      Open an Account
    • RESEARCH & EDUCATION
      RESEARCH & EDUCATION

      Our Research and Education center offers daily updates on all the major trading sessions along with multiple daily briefings on all critical market events which daily shape the global markets.

      Manned by 20 multilingual market professionals we present a diversified educational knowledge base to empower our customers with a competitive advantage.

      Risk Warning: Trading on margin products involves a high level of risk.

      Research
      • Markets Overview
      • Discover
        NEW
      • XM Research
      • Trade Ideas
      • Technical Summaries
      • Economic Calendar
      • XM TV
      • Podcast
      Learning Center
      • XM Live
      • Live Education
      • Live Education Schedule
      • Educational Videos
      • Forex & CFDs Webinars
      • Platform Tutorials
      Tools
      • Trading Tools
      • MQL5
      • Forex Calculators

      Access the global markets instantly with the XM MT4 or MT5 trading platforms.

      Open an Account
    • PROMOTIONS
    • ABOUT US
      ABOUT US

      XM sets high standards to its services because quality is just as decisive for us as for our clients. We believe that versatile financial services require versatility in thinking and a unified policy of business principles.

      Our mission is to keep pace with global market demands and approach our clients’ investment goals with an open mind.

      Risk Warning: Trading on margin products involves a high level of risk.

      ABOUT US
      • Who is XM Group?
      • Regulation
      • Legal Documents
      • Company News
      • Corporate Social Responsibility
      • Contact
      • Careers
      • XM Awards
      • Complaints

      Access the global markets instantly with the XM MT4 or MT5 trading platforms.

      Open an Account
    • PARTNERSHIPS
    • Home
    • Member Login
    • Deposit Funds
    • Promotions
    • Trading
      • Accounts
      • Trading Account Types
      • Instruments
      • Forex Trading
      • Stocks
      • Commodities
      • Equity Indices
      • Precious Metals
      • Energies
      • Trading Conditions
      • Execution Policy
      • Spreads
      • Overnight Positions
      • Trading Hours
    • Platforms
    • Research & Education
      • Research
      • Markets Overview
      • Discover
        NEW
      • XM Research
      • Trade Ideas
      • Technical Summaries
      • Economic Calendar
      • XM TV
      • Podcast
      • Learning Center
      • XM Live
      • Live Education
      • Live Education Schedule
      • Educational Videos
      • Forex & CFDs Webinars
      • Platform Tutorials
      • Tools
      • Trading Tools
      • MQL5
      • Forex Calculators
    • About Us
      • About XM
      • Who is XM Group?
      • Corporate Social Responsibility
      • Careers
      • Complaints
      • Contact
      • Regulation
      • Legal Documents
      • Company News
      • XM Awards
    • Help Center
    • Partnerships
    Member Login

    Vulnerability Disclosure Policy

    1. XM
    2. Vulnerability Disclosure Policy
    Contact Us

    1. Introduction

    The Trading Point Group (hereinafter “Trading Point”) recognizes the need to approach the cybersecurity community to protect customer data and work together to create more secure solutions and applications. This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preferences in how to submit discovered vulnerabilities to us.

    Researchers are welcome to voluntarily report vulnerabilities they can find connected to the Trading Point systems. This policy describes what systems and types of research are covered under this policy and how to submit vulnerability reports to us.

    The submission of vulnerability reports is subject to the terms and conditions set forth on this page, and by submitting a vulnerability report to Trading Point the researchers acknowledge that they have read and agreed to these terms and conditions.

    2. Terms and Conditions

    2.1. Safe Harbor / Authorization

    When conducting vulnerability research, showing good faith effort to comply with this policy, we consider your research to be:

    • Authorized concerning any applicable anti-hacking laws and we will not recommend or pursue legal action against you for your research.

    • Authorized concerning any relevant anti-circumvention laws and we will not bring a claim against you for circumvention of technology controls.

    • Lawful, helpful to the overall security of the Internet, and conducted in good faith.

    You are expected to comply with all applicable laws. If legal action is initiated by a third party against you for activities that you have conducted in good faith in accordance with this policy, we will make this authorization known.

    If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels (as determined herein below) before going any further.

    Note that the Safe Harbor applies only to legal claims under the control of the organization participating in this policy, and that the policy does not bind independent third parties.

    2.2. Guidelines

    Under this policy, “research” means activities in which you:

    • Notify us as soon as possible after you discover a real or potential security issue.

    • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.

    • Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems.

    You are also requested to:

    • Play by the rules, including following this policy and any other relevant agreements. If there is any inconsistency between this policy and any other applicable terms, the terms of this policy will prevail.

    • Only interact with your own test accounts.

    • Limit account creation to two (2) accounts total for any testing.

    • Use only the Official Channels to disclose and/or discuss vulnerability information with us.

    • Submit one vulnerability per report, unless you need to chain vulnerabilities to demonstrate the impact.

    • Securely delete all data retrieved during research once the report is submitted.

    • Perform testing only on in-scope systems, and respect systems and activities which are out of scope.

    • Avoid using high-intensity invasive or automated scanning tools to find vulnerabilities.

    • Do not publicly disclose any vulnerability without Trading Point's prior written consent.

    • Do not perform any "Denial of Service" attack.

    • Do not perform social engineering and/or physical security attacks against Trading Point's offices, users, or employees.

    • Do not perform automated/scripted testing of web forms, especially "Contact Us" forms that are designed for customers to contact our Customer Care team.

    Once you’ve established that a vulnerability exists or you unintendedly encounter any sensitive data (including personally identifiable information (PII), financial information, proprietary information, or trade secrets of any party), you must stop your test, notify us immediately, and not disclose this data to anyone else. You should also limit your access to the minimum data required for effectively demonstrating a proof of concept.

    2.3. Reporting a Vulnerability / Official Channels

    Please report security issues / actual or potential vulnerability findings via auvulnerability.disclosure@xm.com, providing all relevant information. The more details you provide, the easier it will be for us to triage and fix the issue.

    To help us triage and prioritize submissions, we recommend that your reports:

    • Describe the location or application path where the vulnerability was discovered and the potential impact of exploitation.

    • Offer a detailed description of the steps needed to reproduce the vulnerability (proof-of-concept scripts or screenshots are helpful).

    • Include as many details as possible.

    • Include the IP address that you were testing from, the email address, user-agent and username(s) used in the trading platform (if any).

    • Be in English, if possible.

    If you think that the vulnerability is serious or it contains sensitive information, you can send a PGP encrypted email to our team using our PGP key.

    2.4. Scope

    a) In-Scope Systems/Services

    Domains Android App iOS App

    https://www.xm.com/au

    https://my.xm.com/au

    XM Android Application (com.xm.webapp)

    XM iOS Application (id1072084799)

    b) Out-of-Scope Systems/Services

    Any service (such as connected services), system, or domain not expressly listed in the "In-Scope Systems/Services” section above, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any). If you are not sure whether a system is in scope or not, contact us at auvulnerability.disclosure@xm.com.

    c) In-Scope Vulnerabilities

    • SQL Injection

    • Cross-Site Scripting (XSS)

    • Remote code execution (RCE)

    • Server-Side Request Forgery (SSRF)

    • Broken authentication and session management

    • Insecure Direct Object Reference (IDOR)

    • Sensitive data exposure

    • Directory/Path traversal

    • Local/Remote File Inclusion

    • Cross-Site Request Forgery (CSRF) with demonstrable high impact

    • Open redirect on sensitive parameters

    • Subdomain takeover (for subdomain takeover add a friendly message like: "We are working on it and we will be back soon.")

    d) Out-of-Scope Vulnerabilities

    Certain vulnerabilities are considered out-of-scope for the Vulnerability Disclosure Program. Those out-of-scope vulnerabilities include, but are not limited to:

    • Mail configuration issues including SPF, DKIM, DMARC settings

    • Clickjacking vulnerabilities that do not lead to sensitive actions, such as account modification

    • Self-XSS (i.e., where a user would need to be tricked into pasting code into their web browser)

    • Content spoofing where the resulting impact is minimal (e.g., non-HTML text injection)

    • Cross-Site Request Forgery (CSRF) where the resulting impact is minimal (e.g., CSRF in login or logout forms)

    • Open redirect - unless an additional security impact can be demonstrated

    • CRLF attacks where the resulting impact is minimal

    • Host header injection where the resulting impact is minimal

    • Missing HttpOnly or Secure flags on non-sensitive cookies

    • Missing best practices in SSL/TLS configuration and ciphers

    • Missing or misconfigured HTTP security headers (e.g., CSP, HSTS)

    • Forms missing Captcha controls

    • Username/email enumeration via Login Page error message

    • Username/email enumeration via Forgot Password error message

    • Issues that require unlikely user interaction

    • Password complexity or any other issue related to account or password policies

    • Lack of session timeout

    • Brute-force attacks

    • Rate limit issues for non-critical actions

    • WordPress vulnerabilities without proof of exploitability

    • Vulnerable software version disclosure without proof of exploitability

    • Any activity that could lead to the disruption of our service (DoS)

    • Lack of Root protection / Bypass of Root protection (mobile applications)

    • Lack of SSL certificate pinning / Bypass of SSL certificate pinning (mobile applications)

    • Lack of code obfuscation (mobile applications)

    2.5. Response Times

    Trading Point is committed to coordinating with you as openly and as quickly as possible and will make best efforts to meet the following response targets for researchers participating in our program:

    • Time to first response (from day of submission of the report) is three (3) business days. Within three business days, we will acknowledge that your report has been received.

    • Time to triage (from report submission) is five (5) business days.

    To the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, as well as issues or challenges that may delay resolution. We’ll try to keep you informed about our progress throughout the process.

    3. Rewards

    We value those who take the time and effort to report security vulnerabilities according to this policy. However, currently we do not offer any rewards for vulnerability disclosures. This is subject to change in the future.

    4. Feedback

    If you wish to provide feedback or suggestions on this policy, please contact us at auvulnerability.disclosure@xm.com.

    Thank you for helping keep Trading Point and our users safe.

    5. PGP key fingerprint

    F096 4A0E CA36 A301 18DF A742 DE89 DE1C 5283 013F

    Download TP Vulnerability Disclosure PGP key

    Note: Please encrypt your messages with the above PGP key and include your own public key in the email.

    Open an AccountForex Trading involves significant risk to your invested capital Open a Demo Account$100,000 Virtual Balance Member Login
    • About Us

    • Who is XM?
    • Regulation
    • Legal Documents
    • XM Group News
    • Contact
    • Careers
    • XM Awards
    • Complaints
    • Trading Accounts
    • Trading Account Types
    • Trading Instruments
    • Forex Trading
    • Stocks
    • Commodities
    • Equity Indices
    • Precious Metals
    • Energies
    • Trading Conditions
    • Execution Policy
    • Spreads
    • Overnight Positions
    • Trading Hours
    • MT4 Platforms
    • MT4 for PC
    • MT4 for Mac
    • MT4 WebTrader
    • MT4 for iPad
    • MT4 for iPhone
    • MT4 for Android
    • MT4 for Android Tablet
    • MT5 Platforms
    • MT5 for PC
    • MT5 for Mac
    • MT5 WebTrader
    • MT5 for iPad
    • MT5 for iPhone
    • MT5 for Android
    • MT5 for Android Tablet
    • About XM
    • XM Awards
    • Contact
    • Help Center
    metaquotes
    verisign
    unicef
    investors
    Great Place to Work Great Place to Work
    Follow us:

    © 2023 XM is a trading name of Trading Point Holdings Ltd. All rights reserved. | Privacy Policy | Cookie Policy | Vulnerability Policy | Terms and Conditions

    trading-point

    Legal: This website is operated by Trading Point of Financial Instruments Pty Limited, ACN 164 367 113, AFSL 443670, with registered address Level 13, 333, George Street, Sydney, NSW 2000, Australia.

    Risk Warning: Margin forex and CFD trading involves significant risk to your invested capital. Our FSG and PDS should be considered before deciding to enter into any derivative transactions with Trading Point of Financial Instruments Pty Limited.

    The information on this site is not directed at residents of the United States or any particular country outside Australia and is not intended for distribution to, or use by, any person in any country or jurisdiction where such distribution or use would be contrary to local law or regulation.

    xm logo

    We respect your privacy

    We use cookies to ensure the best possible browsing experience. Some are needed for essential features like login sessions, while others help us provide you with content and marketing more closely tailored to your needs. Accepting all cookies enables us to enhance your experience further. Please note, some of these may be third-party cookies. You can modify your cookie preferences by clicking the button below. For more information, please see our Cookie Policy.

    Your cookie settings

    • What are Cookies?
    • Why are cookies useful?
    • Change Settings

    What are Cookies?

    Cookies are small data files. When you visit a website, the website sends the cookie to your computer. Your computer stores it in a file located inside your web browser.

    Cookies do not transfer viruses or malware to your computer. Because the data in a cookie does not change when it travels back and forth, it has no way to affect how your computer runs, but they act more like logs (i.e. they record user activity and remember stateful information) and they get updated every time you visit a website.

    We may obtain information about you by accessing cookies, sent by our website. Different types of cookies keep track of different activities. For example, session cookies are used only when a person is actively navigating a website. Once you leave the website, the session cookie disappears.

    Why are cookies useful?

    We use functional cookies to analyse how visitors use our website, as well as track and improve our website’s performance and function. This allows us to provide a high-quality customer experience by quickly identifying and fixing any issues that may arise. For example, we might use cookies to keep track of which website pages are most popular and which method of linking between website pages is most effective. The latter also helps us to track if you were referred to us by another website and improve our future advertising campaigns.

    Another use of cookies is to store your log in sessions, meaning that when you log in to the Members Area to deposit funds, a "session cookie" is set so that the website remembers that you have already logged in. If the website did not set this cookie, you will be asked for your login and password on each new page as you progress through the funding process.

    In addition, functional cookies, for example, are used to allow us to remember your preferences and identify you as a user, ensure your information is secure and operate more reliably and efficiently. For example, cookies save you the trouble of typing in your username every time you access our trading platform, and recall your preferences, such as which language you wish to see when you log in.

    Here is an overview of some of the functions our cookies provide us with:

    • Verifying your identity and detecting the country you are currently visiting from
    • Checking browser type and device
    • Tracking which site the user was referred from
    • Allowing third parties to customize content accordingly

    This website uses Google Analytics, a web analytics service provided by Google, Inc. ("Google"). Google Analytics uses analytical cookies placed on your computer, to help the website analyze a user's use of the website. The information generated by the cookie about your use of the website (including your IP address) may be transmitted to and stored by Google on their servers. Google may use this information to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage. Google may also transfer this information to third parties, where required to do so by law, or where such third parties process the information on behalf of Google. Google will not associate your IP address with any other data held. By using this website, you give your consent to Google to process data about you in the manner and for the purposes set out above.

    Change Settings

    Please select which types of cookies you want to be stored on your device.




    xm logo

    We are using cookies to give you the best experience on our website. Read more or change your cookie settings.

    Risk Warning: Your capital is at risk. Leveraged products may not be suitable for everyone. Please consider our Risk Disclosure.

    XM Live Chat

    By clicking "Enter", you agree to the personal data you provide via live chat to be processed by Trading Point of Financial Instruments Pty Ltd, as per the Company's Privacy Policy, to receive assistance from our Customer Experience Department.

    If you do not give your consent to the above, you may alternatively contact us via the Members Area or at ausupport@xm.com.

    Enter

    Please enter your contact information. If you already have an XM account, please state your account ID so that our support team can provide you with the best service possible.

    • Existing Client
    • New Client