samtradingbotsAll policies← Home
Trust

Security

Last updated July 2026

How your account and credentials are protected. Security is layered, and it reflects how the platform is actually built.

We never take custody of your funds

Your capital stays with your own broker at all times. We provide software and execution monitoring — we cannot withdraw or move your funds.

Broker credentials are sealed as ciphertext

On the live product, MetaTrader 5 trading credentials are sealed into a KMS key envelope as ciphertext on submit. They are never stored in plain text and never logged, and are used only to execute copying on your account. No broker password is ever requested on the marketing site.

No secrets in the browser

Payment and infrastructure secrets live server-side only. The site enforces a strict Content-Security-Policy, ships no unaudited third-party scripts, and serves over HTTPS with HSTS.

Isolation per account

Each strategy runs under its own magic-number isolation, and each customer account executes separately. Customer data is protected by row-level security so you only ever see your own records.

Fail-closed by default

Copying is off unless your subscription entitles it, and the signal pipeline drops any malformed or unqualified event rather than guessing. The safe state is "do nothing".

You stay in control

You can pause copying instantly, disconnect your broker, or cancel at any time. An emergency pause stops new copying while open trades are still managed to exit.

No system is perfectly secure. If you believe you've found a vulnerability, please contact [OWNER: security@your-domain] — we welcome responsible disclosure.

Trading involves risk of loss. Nothing on this page is investment advice. Automated copy trading does not remove market risk, and returns are not guaranteed. Past performance does not predict future results.