Security


You're connecting brokerage accounts to us, so it's fair to ask exactly what we can do with them and how we protect that access.

We never hold your funds

ezpztrader is non-custodial. Your money stays in your own brokerage accounts. The authorisation you grant covers reading balances, positions and orders, and placing or cancelling trades. It does not permit deposits, withdrawals, or transfers of any kind — we could not move your money even if we wanted to.

Credentials

Where a broker supports OAuth, we store only the access token they issue and never see your broker password. Where a broker requires API keys, those keys are encrypted at rest and are only decrypted at the moment an order is placed. You can revoke any connection from your dashboard, or from the broker's own settings, at any time.

Data protection

  • All traffic is encrypted in transit with TLS.
  • Data is encrypted at rest on disk.
  • Account passwords are hashed with a modern, deliberately slow algorithm — they are never stored in a readable form and cannot be recovered, only reset.
  • Two-factor authentication is available on your ezpztrader account and we recommend enabling it.

Operational practice

  • Development and production environments are separated.
  • Administrative access requires multi-factor authentication.
  • Application and access logs are centralised so unusual activity is visible.
  • Dependencies are monitored for known vulnerabilities.

Reporting a vulnerability

If you believe you've found a security issue, email info@ezpztrader.com with enough detail to reproduce it. We'll acknowledge your report and keep you updated while we investigate. Please give us a reasonable window to fix the issue before disclosing it publicly.