COMPANYSecurity

Your clips are yours and only yours.

Recording trades is intimate data. We treat it that way.

Storage

Access control

Authentication

Sign-in via Google OAuth (web) and email + password (mobile). All sessions managed by Supabase Auth. JWTs stored in localStorage with refresh-token rotation.

Vulnerability disclosure

If you've found a vulnerability, email security@tradeanderror.com with details. We acknowledge within 24 hours and aim to ship a fix within 7 days for high-severity issues. Bounty program: in preparation.

Audit & compliance