Security
How your account and credentials are protected. Security is layered, and it reflects how the platform is actually built.
We never take custody of your funds
Your capital stays with your own broker at all times. We provide software and execution monitoring — we cannot withdraw or move your funds.
Broker credentials are sealed as ciphertext
On the live product, MetaTrader 5 trading credentials are sealed into a KMS key envelope as ciphertext on submit. They are never stored in plain text and never logged, and are used only to execute copying on your account. No broker password is ever requested on the marketing site.
No secrets in the browser
Payment and infrastructure secrets live server-side only. The site enforces a strict Content-Security-Policy, ships no unaudited third-party scripts, and serves over HTTPS with HSTS.
Isolation per account
Each strategy runs under its own magic-number isolation, and each customer account executes separately. Customer data is protected by row-level security so you only ever see your own records.
Fail-closed by default
Copying is off unless your subscription entitles it, and the signal pipeline drops any malformed or unqualified event rather than guessing. The safe state is "do nothing".
You stay in control
You can pause copying instantly, disconnect your broker, or cancel at any time. An emergency pause stops new copying while open trades are still managed to exit.
No system is perfectly secure. If you believe you've found a vulnerability, please contact [OWNER: security@your-domain] — we welcome responsible disclosure.
Trading involves risk of loss. Nothing on this page is investment advice. Automated copy trading does not remove market risk, and returns are not guaranteed. Past performance does not predict future results.