Security Overview
Security posture, vulnerability reporting, user responsibilities, local-device boundaries, and incident handling
Page sections
Security posture
OptionForge uses reasonable administrative, technical, and organizational safeguards for the website, support handling, policy publication, package distribution, diagnostics, and public contact workflows. No website, email system, device, or internet transmission is guaranteed to be perfectly secure.
Local-device boundary
The desktop app runs on the user’s Windows device. Users are responsible for device security, Windows account protection, browser/store account protection, backups, access controls, and protecting local project files.
Sensitive data handling
Users should not send broker passwords, API secrets, private keys, authentication tokens, full account numbers, or full payment-card data to support. Redact sensitive screenshots and logs before sending.
Vulnerability reporting
Security reports should be sent to [email protected] with “Security report” in the subject and enough detail for safe reproduction. Do not perform destructive testing, privacy-invasive testing, or unauthorized access.
Incident handling
If a credible issue is reported, OptionForge may investigate, request more information, deploy fixes, update documentation, rotate affected secrets where applicable, and notify affected parties or platforms where required.
Third-party services
Microsoft Store, hosting, email, analytics, and other service providers may have their own security controls, privacy documentation, and account procedures.