Security is an ongoing practice

Protect the account. Test the execution. Report the gap.

We apply layered controls to the website and copier infrastructure, and publish honest operational status. We do not claim an independent security certification until one is completed.

Broker secrets encrypted

Broker credentials that must be reused are encrypted with AES-256-GCM. Production refuses to store them without a dedicated encryption key.

Scoped access

Browser sessions, copier tokens, machine endpoints, and scheduled jobs use separate authentication paths. Database service access stays server-side.

Paper-first controls

Execution products expose account, lot, symbol, and paper-account guardrails. Users should still validate every broker workflow on demo or paper first.

Responsible disclosure

If you believe you found a security vulnerability, email the affected URL, reproduction steps, impact, and safe supporting evidence. Do not access other users' data, execute live trades, disrupt availability, or publish the issue before we have had a reasonable chance to investigate.

Email a security report

Never send passwords, copier tokens, private keys, OTP codes, or full payment details.