FRAUD RISK REDUCTION AND CONTROL MEASURES Version for publication on ascaron.online Last updated: September 14, 2026 The Operator applies proportionate measures to protect accounts, payments, and the game economy. This document describes the general approach without disclosing parameters that could be used to evade controls. 1 Responsible operator The measures are applied by Knuth Capital LLC FZ, Company No. 2531107, Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, UAE. Suspected transactions may be reported to info@ascaron.online. 2 Account protection • limiting and logging failed sign-in attempts • notifications or additional review for unusual sign-ins • secure password storage and separation of administrative access • temporary session suspension where account takeover is suspected 3 Payment controls • checking the status and uniqueness of each transaction number • limiting the frequency and amount of repeated attempts • checking inconsistencies between the account, device, region, and payment transaction • requesting additional bank verification where available • holding crediting in high-risk cases until review is completed 4 Game economy controls The Operator may analyse unusual creation, transfer, and spending of value, linked account chains, duplicated items, and exploitation of errors. Improperly obtained value may be isolated or removed after review. 5 Automated rules Systems may assign a risk level to an operation and automatically require additional review. The Operator does not publish control thresholds or signatures. A material adverse decision is reviewed by a person at the User's request where law requires or reasonably permits it. 6 Manual review An authorised employee compares account, payment, and game event logs. Only information necessary for the review is requested. The Operator never asks for a full card number, CVC or CVV, a banking password, or a one-time code. 7 Possible measures Until review is completed, the Operator may hold delivery, restrict a disputed balance, end active sessions, or temporarily limit paid functions or the account. After review, the restriction is removed, the operation is completed, funds are refunded, or sanctions are applied under the Rules. Each measure must match the risk level. 8 Refunds and disputes The User should report a duplicate charge, failure to deliver, or unauthorised transaction without delay. Repeated receipt of both the product and a refund, knowingly false payment disputes, or use of another person's payment instrument may result in account restrictions and disclosure to competent authorities as permitted by law. 9 Confidentiality Anti-fraud data is used only for security, dispute resolution, contract performance, and legal compliance. Access is limited by role. Retention follows the Privacy Policy and the nature of the incident. 10 User contact If a transaction is stopped or an account is restricted, the User may contact info@ascaron.online with the login, transaction number, date, and a description. Support communicates the result within limits that do not disclose security methods or another person's data. 11 Review of controls The Operator regularly reviews risk rules, access rights, logs, and incident outcomes, corrects false positives, and updates controls in response to new threats.