TradeInsights is designed for post-trade analytics. It does not expose an order-entry, transfer, or withdrawal workflow. Connection capabilities still depend on the provider, so use read-only permissions whenever they are available.
TradeInsights asks for the minimum permissions needed to retrieve eligible history. The product does not need trading, transfer, or withdrawal permissions.
Use an MT4/MT5 investor password and read-only crypto keys. OAuth and personal-token scope behavior is controlled by the provider; review the provider's authorization screen before approving it.
Direct-connection secrets are protected with authenticated application-layer encryption before storage and are not returned to the browser after submission. Provider-managed OAuth tokens remain subject to the provider integration's storage design.
The server reveals a stored direct credential only when it needs to validate or refresh that connection. Connection responses expose status and safe account labels, not API keys, API secrets, or passphrases.
The production site and supported external API connections use HTTPS. Do not submit credentials if your browser reports a certificate or connection warning.
TradeInsights stores account passwords as salted one-way hashes and supports legacy password hashes during sign-in migration; it does not need the original password to authenticate you.
TradeInsights runs its application on Railway and stores application data in Postgres. Access to production services is controlled through deployment credentials and environment configuration.
Retention and deletion depend on the data type, legal obligations, and active provider records. See the Privacy Policy for the current customer-facing terms rather than relying on a fixed backup-retention promise.
SageAI requests can include the question you submit and selected trading context needed to generate a response. Avoid placing credentials, account numbers, or other unnecessary personal data in a prompt.
External AI processing is governed by the applicable provider terms and the TradeInsights Privacy Policy. An AI response is analytical assistance, not individualized financial advice.
TradeInsights will assess suspected incidents and provide notices when required by applicable law and the facts of the incident.
We do not have a public bug bounty programme. Send responsible disclosures to [email protected] and avoid accessing or retaining other users' data.
We take security seriously. If you have a question, a responsible disclosure, or you just want to understand how something works, reach out.
Contact security team