Help Article
Broker API Security
How We Handle Broker API Access
Your broker credentials are protected with enterprise-grade security.
Read-Only Access
We request ONLY read access to:
- ✅ View trade history
- ✅ View positions
- ✅ View account metadata
We CANNOT:
- ❌ Execute trades
- ❌ Transfer funds
- ❌ Modify orders
- ❌ Access login credentials
API Token Storage
- Encrypted using AES-256
- Stored in isolated, secure database
- Never logged or exposed
- Decrypted only when syncing
Disconnecting Brokers
To revoke access:
- Go to Settings → Broker Connections
- Click "Disconnect" on the broker
- Confirm disconnection
- Token immediately invalidated
Our Commitment
We will never:
- Sell your API access
- Share tokens with third parties
- Use access beyond stated purposes
- Store more than necessary