Secure & Encrypted

Your data and credentials are always safe.

Security is foundational to Tradeify. All broker credentials are encrypted at rest and in transit. Multi-factor authentication, session management, and SOC 2 compliant infrastructure ensure your account stays protected at every layer.

Security at Every Layer

AES-256 Encryption

Broker API keys and sensitive credentials are encrypted using industry-standard AES-256 encryption at rest.

TLS 1.3 In Transit

All communication between your browser and our servers uses TLS 1.3 — the latest transport security standard.

Two-Factor Auth (2FA)

Protect your account with TOTP-based two-factor authentication using apps like Google Authenticator or Authy.

JWT Session Management

Secure, stateless sessions using JSON Web Tokens. Tokens expire and refresh automatically.

Password Hashing

Passwords are hashed with bcrypt using adaptive cost factors. We never store plain-text passwords.

SOC 2 Infrastructure

Our infrastructure follows SOC 2 compliance standards with regular security audits and monitoring.

Authentication Flow

Here's how we keep your account secure from sign-up to every trading session.

1

Account Creation

Your password is hashed with bcrypt before being stored. Email verification confirms your identity.

2

Login

Credentials are verified server-side. On success, a signed JWT token is issued with a configurable expiry.

3

2FA Challenge (optional)

If enabled, a TOTP code from your authenticator app is required before the session is established.

4

Broker Connection

API keys are encrypted with AES-256 and stored securely. OAuth tokens are refreshed automatically.

5

Session Management

JWTs are validated on every API request. Expired tokens trigger automatic re-authentication.

What We Protect

User passwords (bcrypt hashed)
Broker API keys (AES-256 encrypted)
OAuth access & refresh tokens
Personal information (email, name)
Trading history & strategy configs
Session tokens (JWT with expiry)

Trade with peace of mind

Your security is our top priority, from your first login to every trade.