Security & Privacy

Security is designed in from the start. This page describes our approach; formal certifications require independent audit.

Authentication

Email/password with verification, session management, sign-out-all-devices, optional MFA for users and required MFA for administrators.

Data isolation

Row-Level Security ensures each user can only read and edit their own data. Central market data is read-only for users.

Payments

We never store full card numbers. Payments are processed by Stripe. Membership status is verified server-side from the database, never trusted from the client.

Protecting your data

We collect only what we need, mask sensitive values, never log passwords or tokens, use secure cookies, CSRF protection, a content security policy and rate limiting.

Your controls

Export or delete your data, revoke sessions and manage consent at any time from Settings.