Home · The Ordane Journal · Rules and Mechanics · Can You Use a VPN With a Prop Firm Account?
Can You Use a VPN With a Prop Firm Account?
Ordane accounts operate on simulated capital. No live funds are traded and no deposits are accepted. Payouts depend on simulated performance under Rulebook v1.0; no level of performance is typical or assured.
Ordane sells one product, the Ordane Instant Account: direct access, no evaluation phase and no challenge, on simulated capital.
What Does a VPN Change for a Prop Firm Login?
ESMA's product-intervention notice states that CFDs are complex instruments and come with a high risk of losing money rapidly due to leverage (ESMA, retrieved 2026-08-10). That leverage risk is the independent frame behind any prop CFD-style ticket.
Prop firm VPN rules are not universal. Related buyer questions include the prop firm IP address change rule, whether a firm will ban a VPN login, and how to notify a prop firm before travel. Whether you can trade a prop firm account while traveling, or complete a prop firm login from another country, depends on the firm's written VPN, travel, device-control and country-eligibility clauses, not on what a VPN feels like it hides.
A VPN can change the IP address a service observes when you connect. That does not, by itself, identify who is holding the phone or prove how the account was authenticated. The National Institute of Standards and Technology (NIST) defines a virtual private network as "A virtual network built on top of existing networks that can provide a secure communications mechanism for data and IP information transmitted between networks" (NIST CSRC Glossary, retrieved 2026-08-03). Nothing in that definition is about hiding, cheating, or evading a rule.
The practical consequence is narrow and specific. Microsoft documents plainly that "You can change your IP address by using a VPN" (Microsoft Learn, retrieved 2026-08-03). So a VPN changes one observed network field. Other session attributes may still be recorded separately. This is the same distinction that matters when a firm evaluates any other rule silence, the kind covered in how to audit a prop firm before you pay: read what is written, not what feels intuitive.
Why Do Firms Review Location Changes?
Because location changes are a cheap and useful signal, and because some of the questions behind them are not the firm's discretion at all.
Start with the security layer. NIST states that "authentication from an unexpected geolocation or IP address block (e.g., a cloud service) might prompt the use of additional risk-based controls" (NIST SP 800-63B-4, retrieved 2026-08-03). That is the standard writing down the exact behavior you are worried about: a new location can trigger extra checks. Notice the verb. It prompts controls. It does not establish wrongdoing.
The same standard lists what a system may watch during a session: "Device and browser characteristics (e.g., accepted languages) / Geolocation / IP address characteristics (e.g., whether the IP address is in a block known for abuse)" (NIST SP 800-63B-4, retrieved 2026-08-03). Three signals, evaluated together. A VPN is documented to change the observed IP; the other signals are still evaluated separately, which is one reason a VPN login can look unusual without proving fraud.
Identity, Account Control and Country Eligibility
Three different compliance questions hide behind one flag, and they have different answers and different consequences.
The first is identity. Is the person operating this account the person who was verified? That question is answered by authenticators and by identity checks, not by geography.
The second is account control. Is the account being operated by the buyer, or has someone else been handed the credentials? A location change is one input to that question. It is a weak input on its own, which is why the surrounding evidence matters so much.
The third is country eligibility, and this is the one that is genuinely not negotiable. Some jurisdictions are excluded from a service entirely for sanctions reasons, and the firm does not get discretion over it. The Office of Foreign Assets Control (OFAC) guidance for the virtual-currency industry describes companies identifying IP misattribution by "screening IP addresses against known virtual private network (VPN) IP addresses and identifying improbable logins" (OFAC Sanctions Compliance Guidance, retrieved 2026-08-03). Read that carefully: the concern is not privacy, it is people using a VPN to appear to be somewhere they are permitted to be when they are not. If you are physically in an excluded country, no VPN configuration makes that compliant, and a VPN login from an excluded jurisdiction is one documented scenario where the tool can convert an otherwise permitted activity into a serious compliance problem.
Check country eligibility as a separate question from VPN use, because they fail for different reasons and only one of them can be fixed by turning something off.
A Review Signal Is Not Proof of a Violation
The systems that flag travel already assume they will be wrong sometimes. Microsoft's atypical-travel detection is documented to work like this: "The algorithm ignores obvious 'false positives' contributing to the impossible travel conditions, such as VPNs" (Microsoft Entra ID Protection, retrieved 2026-08-03).
That is a vendor of one of the largest identity platforms in the world stating in its own documentation that VPN-driven location jumps are a known false-positive class. A flag is a request for context. Your job is to have the context ready before the request arrives.
What Should You Check Before Traveling?
Read four things separately in your firm's written rules. Not one thing four times. Four distinct clauses that may exist independently, or may not exist at all, and whose silence means different things. The same discipline applies to reading a firm's news-trading buffer window or its stance on overnight and weekend holding: a closed list only tells you what it names.
| What to check | Where the answer must come from |
|---|---|
| VPN or proxy use | The written rule text, cited by section number |
| Device and account control | The clause covering who may operate the account |
| Country of residence versus country of physical presence | The eligibility or restricted-jurisdiction clause |
| Physical-location wording | The exact phrasing: residence, presence, or connection |
| What to check | Evidence to preserve |
|---|---|
| VPN or proxy use | Dated copy or screenshot of the clause |
| Device and account control | Device ownership records; login events tied to your authenticators (NIST CSRC Glossary, retrieved 2026-08-03) |
| Country of residence versus country of physical presence | Travel dates, itinerary, accommodation records |
| Physical-location wording | Copy of the sentence, verbatim |
| What to check | Action before your first foreign login |
|---|---|
| VPN or proxy use | If no clause exists, ask support in writing before you rely on it |
| Device and account control | Confirm nobody else will have credentials while you travel |
| Country of residence versus country of physical presence | Verify the destination is not excluded, per the sanctions concern documented by OFAC (retrieved 2026-08-03) |
| Physical-location wording | Note which of the three words the rule uses, because they are not synonyms |
That last row decides more disputes than the VPN question does. A rule that restricts your country of residence governs where you live. A rule that restricts your physical presence governs where you sit when you place a trade. A rule that restricts your connection governs the network path. A firm that has written only one of those three has said nothing about the other two, and you should not fill the gap with an assumption.
Check VPN, Device, Residence and Physical-Location Wording Separately
Do this before you leave, not from a hotel:
- Save the current rule text with today's date. Rules change; your saved copy records the text you relied on when asking, while the signup version remains the governing contract.
- Search that text for the words VPN, proxy, IP, country, jurisdiction, resident, residence, and located. Record which appear and which do not.
- Write down what the document is silent about. Silence is a real finding, and it is the finding you will need in writing from support.
- Confirm your destination is not on any restricted-jurisdiction list the firm publishes.
- Decide, in advance, whether you will run the VPN during trading, and be consistent about it.
If the words VPN and IP appear nowhere in the rules, do not read that as permission or as prohibition. Read it as unwritten, then get it written.
How Do You Ask Support a Question That Survives Review?
Most support answers are useless because most questions are vague. "Can I use a VPN?" invites a one-word reply that binds nobody. Ask a question whose answer is a rule.
Include five things in a single written message: the exact dates you will be abroad, the countries involved, confirmation that only you will operate the account, whether a VPN will be active, and a request that the reply cite the governing clause by section number.
State Dates, Countries, Device Ownership and VPN Use
A message that works looks roughly like this:
Then send it before you travel, and keep the reply.
Request a Dated Answer Tied to the Governing Rule
A dated answer that names a clause is evidence. An undated reassurance in a chat window is a memory. Ask for the section number and the document version explicitly, and if the reply arrives without them, reply once and ask again.
Chat approvals are the weakest form of permission you can obtain, because the transcript may not survive, and because the person answering may not be authorized to grant an exception to a written rule. Prefer a channel that produces a record you keep, not one that lives on their server.
What Proof Should You Keep?
Keep a timeline, not a pile. The goal is a short, coherent record that answers one question: you controlled the account throughout, and you were where you said you were.
| Evidence | What it establishes |
|---|---|
| Travel dates and itinerary | Your actual physical location over time |
| Your own dated copy of the rule text | Which version you relied on |
| Support correspondence with clause citation | That permission was sought and answered |
| Device records and consistent hardware use | Continuity of the operating device |
| Login events tied to your authenticators | That the authenticators bound to the account were used (NIST); not automatic proof of who sat at the keyboard |
| Evidence | Why it matters in a review |
|---|---|
| Travel dates and itinerary | Distinguishes physical presence from displayed IP, per MaxMind Support (retrieved 2026-08-03) |
| Your own dated copy of the rule text | A rule you saved is a rule you can quote back |
| Support correspondence with clause citation | Converts an assumption into a documented position |
| Device records and consistent hardware use | Device characteristics are a monitored signal, per NIST SP 800-63B-4 (retrieved 2026-08-03) |
| Login events tied to your authenticators | NIST ties authentication to possession and control of authenticators (CSRC Glossary, retrieved 2026-08-03), not to IP location alone |
Consistency of device is quietly useful here. NIST describes device fingerprinting as "collecting and analyzing the hardware and software characteristics of a device in order to create a unique identifier" (NIST SP 800-63A-4, retrieved 2026-08-03). A stable device with a changing IP can be consistent with travel; a simultaneous device and IP change can raise review questions. Neither pattern alone identifies the person at the keyboard. Avoid borrowing a laptop the same week you land in a new country if you want fewer unexplained signal changes.
Protect Personal Data While Preserving a Usable Timeline
Do not over-share. Send what the question requires and nothing more. The UK data-protection principle of data minimisation requires personal data to be "adequate, relevant and limited to what is necessary" (ICO, retrieved 2026-08-03), and that is a sensible standard to apply to your own disclosures too.
Practically: dates and countries, yes. A full passport scan attached to a routine question about VPN policy, no, unless the firm asks for it through a verification process. Redact booking references and payment details from any receipt you send. Keep the unredacted originals yourself. The same minimal-disclosure habit applies when you meet the first-withdrawal checklist: send what the clause requires, nothing more.
What Can Be Claimed About Ordane?
Only what is published, quoted as published.
Ordane's prohibited-practice list is closed. Clause R-6 names six practices: latency, reverse or hedge arbitrage; high-frequency or bulk automated exploitation; copy trading between Ordane accounts; straddling news releases with paired opposing orders; platform or data-feed exploitation; and gap abuse. If a behavior is not listed in that section, it is not a violation. Discretion is not a rule. (Ordane Rulebook v1.0, clause R-6, retrieved 2026-08-03)
The governing document is Ordane Rulebook v1.0, published 2026-07-23. (Ordane Rulebook v1.0, section 6 Changelog, retrieved 2026-08-03)
Use the Closed Rule List Exactly as Published
Read the six items above and notice what is not among them. VPN use is not on that list. IP addresses are not on that list. Country of physical presence is not on that list. Under a closed list, that has a specific meaning: those behaviors are not enumerated violations of R-6.
The Ordane rulebook is public, numbered and versioned, and no rule is ever applied retroactively to an open account. Changes produce a new version with a dated changelog entry, and the version you sign up under is the version that governs your account. (Ordane Rulebook v1.0, notice above section 0, and section 6 Changelog, retrieved 2026-08-03) The governing version remains the one you signed up under; a dated copy saved before travel is evidence of the text you relied on when you asked support, not a substitute for the signup version.
Do Not Invent a VPN Permission, IP Rule or Country Exception
Here is the discipline, and it cuts both ways.
This article will not tell you that Ordane permits VPN use, because that is a permission statement and no published clause grants it. This article will not tell you that Ordane prohibits VPN use either, because no published clause does that.
What is published is the structure of R-6: a closed, numbered list where absence from the list is not a violation. What is also true is that Ordane has not published a separate travel policy, a VPN clause, or a restricted-jurisdiction list, and those are three different absences. An absence is not a permission and it is not a prohibition. It is an unwritten area, and the correct response to an unwritten area is to ask, in writing, and keep the answer.
Two further published facts are worth having in view before your first withdrawal request from abroad. KYC happens once, at the first withdrawal request, not at purchase. There is no re-verification loop at every payout. (ordanemarkets.com, FAQ, retrieved 2026-08-03) And every withdrawal request is approved, or denied in writing citing the exact rule breached by section number, within 24 clock hours. Past that deadline the request is treated as approved and the G-1 clock starts. (Ordane Rulebook v1.0, clause G-0, retrieved 2026-08-03) That denial-in-writing requirement is part of The Ordane Guarantee, and it is the clause that matters most to a traveling trader, because it means a denial has to name a section rather than gesture at suspicion. The same clause is why checking how long a prop firm actually takes to pay matters before you plan a withdrawal around a trip.
Frequently Asked Questions
Is a changing mobile IP the same as a VPN?
A VPN is a chosen routing path that can change the IP a service observes. Microsoft documents that "You can change your IP address by using a VPN" (Microsoft Learn, retrieved 2026-08-03). MaxMind notes that VPN geolocation may resolve the VPN server rather than the end user (MaxMind Support, retrieved 2026-08-03). This article does not claim a separate mechanism for ordinary mobile IP changes; if a firm asks about a non-VPN IP pattern, request the exact log fields they are reviewing and answer only from those records.
Should you disable a VPN before trading?
That depends on your firm's written rule, and it should be a consistent decision rather than a per-session one. If the rules are silent, the practical argument for turning it off during trading is simplicity: fewer conflicting signals to explain later. The argument for leaving it on is that it is a documented security tool by NIST's own definition (NIST CSRC Glossary, retrieved 2026-08-03), and switching it on and off mid-trip produces a jagged pattern that is harder to narrate than a steady one. Whichever you choose, choose it once for the trip and keep a record of the choice.
Can support approve travel by chat?
Treat a chat reply as informal until it is dated, cites the governing clause and version, and exists somewhere you control. A chat message that says "should be fine" is not a rule and will not carry weight in a review. Ask for the section number, keep the transcript or export it yourself, and if the answer arrives without a citation, ask once more.
Will a VPN login get my account closed automatically?
Nothing in the standards suggests automatic closure is the expected outcome of a location change. NIST's language is that an unexpected geolocation "might prompt the use of additional risk-based controls" (NIST SP 800-63B-4, retrieved 2026-08-03), and Microsoft's own detection explicitly discounts VPNs as a false-positive source (Microsoft Entra ID Protection, retrieved 2026-08-03). Expect a question, prepare an answer, and stop expecting a verdict.
What if I am physically in a restricted country?
Then no VPN configuration fixes it, and using one to appear elsewhere is the specific behavior compliance screening is designed to catch. OFAC guidance describes exactly this control: "screening IP addresses against known virtual private network (VPN) IP addresses and identifying improbable logins" (OFAC Sanctions Compliance Guidance, retrieved 2026-08-03). Check eligibility as a separate question, before you book the flight.
The workable position is unglamorous. Read the four clauses separately, save the version you read with today's date, ask one precise question in writing, keep a short timeline, and keep your device the same. Do that and a location flag is easier to answer with records instead of becoming a dispute you cannot document. The review is rarely about the IP string alone; it is about whether your saved rules, travel records and authenticator events give a coherent account of the session.
Worked arithmetic check
Declared inputs for this check only: notional 100000; commission rate 0.0002 per side; two sides in a round-turn.
| Input | Value | Arithmetic |
|---|---|---|
| Notional | 100000 | Declared |
| Rate per side | 0.0002 | Declared |
| Sides | 2 | Declared |
| Round-turn cost | 40 | 100000 x 0.0002 x 2 = 40 |
Arithmetically: 100000 x 0.0002 x 2 = 40 under these declared inputs.
An independent US regulator frames leveraged speculation the same way: like all futures products, speculating in these markets should be considered a high-risk transaction (CFTC, retrieved 2026-08-10).
Sources
- NIST Computer Security Resource Center Glossary, on a virtual private network being a virtual network built on top of existing networks that can provide a secure communications mechanism for data and IP information transmitted between networks. csrc.nist.gov Retrieved 2026-08-03.
- Microsoft Learn, "Simulate risk detections in Microsoft Entra ID Protection", on a VPN being able to change the IP address presented during a sign-in. learn.microsoft.com Retrieved 2026-08-03.
- MaxMind Support, "Geolocation accuracy", on IP geolocation possibly resolving the web server used to run the VPN rather than the VPN user. support.maxmind.com Retrieved 2026-08-03.
- NIST SP 800-63B-4, Authentication Assurance Levels, on authentication from an unexpected geolocation or IP address block possibly prompting the use of additional risk-based controls. pages.nist.gov Retrieved 2026-08-03.
- NIST SP 800-63B-4, Session Management, on device and browser characteristics, geolocation and IP address characteristics being signals that may be evaluated during a session. pages.nist.gov Retrieved 2026-08-03.
- NIST SP 800-63A-4, Identity Proofing and Enrollment, on device fingerprinting being the collection and analysis of the hardware and software characteristics of a device in order to create a unique identifier. pages.nist.gov Retrieved 2026-08-03.
- Microsoft Entra ID Protection, "What are risk detections?", on the atypical-travel algorithm ignoring obvious false positives such as VPNs. learn.microsoft.com Retrieved 2026-08-03.
- U.S. Department of the Treasury, Office of Foreign Assets Control, "Sanctions Compliance Guidance for the Virtual Currency Industry", on screening IP addresses against known virtual private network IP addresses and identifying improbable logins. ofac.treasury.gov Retrieved 2026-08-03.
- Information Commissioner's Office, "Principle (c): Data minimisation", on personal data being adequate, relevant and limited to what is necessary. ico.org.uk Retrieved 2026-08-03.
- Google Account Help, "See devices with account access", on a displayed sign-in location being a nearby place instead of an exact location. support.google.com Retrieved 2026-08-03.
- NIST Computer Security Resource Center Glossary, "authentication", on a claimant proving possession and control of one or more authenticators bound to a subscriber account. csrc.nist.gov Retrieved 2026-08-03.
- Ordane Rulebook v1.0, on the closed prohibited-practice list in clause R-6 and its six named practices, on the governing document being Rulebook v1.0 published 2026-07-23, on clause G-0 requiring every withdrawal request to be approved or denied in writing citing the exact rule breached by section number within 24 clock hours, and on the rulebook being public, numbered, versioned and never applied retroactively to an open account. ordanemarkets.com/rulebook Retrieved 2026-08-03.
- Ordane Markets, homepage FAQ, on KYC happening once, at the first withdrawal request, not at purchase, with no re-verification loop at every payout. ordanemarkets.com Retrieved 2026-08-03.
- ESMA, "Notice of product intervention decisions on CFDs and binary options", on CFDs being complex instruments that come with a high risk of losing money rapidly due to leverage. esma.europa.eu Retrieved 2026-08-10.
- U.S. CFTC, "Customer Advisory: Understand the Risks of Virtual Currency Trading", on speculating in these markets being considered a high-risk transaction, like all futures products. cftc.gov Retrieved 2026-08-10.
Disclaimers
This article is for information only and is not investment, financial, or tax advice.
Ordane accounts operate on simulated capital. No live funds are traded and no deposits are accepted. Payouts depend on simulated performance under Rulebook v1.0; no level of performance is typical or assured.