Encryption & Key Management
Transport security, local-device responsibility, credential handling, API key guidance, secrets, and support redaction guidance.
Last updated: 2026-08-24 · Support: [email protected]
Transport and headers
The website should be served over HTTPS with security headers, HSTS, content-type controls, frame protections, referrer restrictions, and limited browser permissions in the static web app configuration.
Local security responsibility
Local files and logs inherit the security posture of the customer device, Windows account, disk encryption, file permissions, antivirus configuration, cloud sync, and backups. Customers should secure sensitive trading and portfolio records accordingly.
Secrets and support
Customers should not send passwords, private keys, seed phrases, brokerage credentials, full payment-card numbers, Microsoft account passwords, or private API keys by ordinary support email. Logs and screenshots should be redacted before sharing.