What protects your account
Written out in full, because "bank-grade encryption" tells you nothing. If something here is unclear, that is a documentation bug — write in and we will fix it.
Signed commands
Every response the connector receives is HMAC-signed with your license secret. The connector verifies the signature before it acts. A hijacked DNS entry, a compromised proxy or a man-in-the-middle cannot inject a trade into your terminal.
Exactly-once execution
Each signal carries an unguessable UUID. The connector keeps the last 500 in a ring buffer mirrored into a terminal global variable, so a restart mid-poll cannot double-fire. Duplicate execution is the one bug that costs real money, so it is tested deliberately and repeatedly.
Account binding
A license runs only on the MetaTrader account numbers you bind to it. Binding a new one takes an explicit action in the portal and sends you an email. An unbound account gets a clear "not authorised" state on the chart — never a silent no-op.
Kill switch
Freeze a license and every terminal running it stops within one poll cycle, which is under a second by default. Enforcement is server-side at handshake, at pull and at fan-out, never in the interface alone.
Signals expire
Undelivered signals carry a time-to-live, 60 seconds by default. A queued entry firing ten minutes later after a reconnect is more dangerous than one that never fires, so it is expired and logged as expired.
We never hold broker credentials
The connector places orders from inside your own terminal. There is no field anywhere in this product for your MetaTrader password or investor password, because we never need one.
Your login
| Password storage | Argon2id, tuned to roughly 100 ms, minimum 12 characters, checked against known breached passwords using a k-anonymity range query so your password never leaves this server. |
| Sessions | 15-minute access tokens with rotating 30-day refresh tokens. Reuse detection: replaying an old refresh token invalidates the entire family and alerts you. |
| Two-factor | TOTP with encrypted recovery codes. Compulsory on admin accounts. Device list with individual revoke and sign-out-everywhere. |
| Login hardening | Progressive delay then temporary lockout, CAPTCHA after repeated failures, and identical responses and timing for an unknown email versus a wrong password so the form cannot be used to enumerate accounts. |
Your data
| In transit | TLS 1.3 only, HSTS preload, modern ciphers, no downgrade path. |
| At rest | Disk encryption plus field-level encryption for license secrets, API keys and two-factor seeds. |
| Backups | Encrypted nightly to off-server storage, 30-day retention, with a restore that is actually tested. An untested backup is not a backup. |
| Minimisation | No card data is ever stored. Full license keys and auth headers are never logged, and secrets are redacted from tracebacks. |
| Your rights | Export and delete endpoints in the portal. Deleted personal data is gone within 30 days. |
For the paranoid advanced
HMAC alert signing
Beyond the shared secret, you can require every inbound alert to carry
sig=HMAC_SHA256(secret, body + timestamp) with a ±60 second window and a nonce
cache. That removes replay attacks outright, including from anyone who can read your webhook URL.
Anomaly detection
We alert on the same license polling from many distinct IP addresses or account numbers at once, on a spike in rejections, on repeated auth failures, and on a license first used from a new country. Those are the signatures of credential sharing and of theft.
- Append-only audit log on every sensitive action
- IP allowlist available per license
- Admin surface is a separate subdomain with its own allowlist and mandatory two-factor