Skip to main content
HomeSecurity
Security controls · evidence in progress

We handle your keys. Never your funds.

PipSync holds broker API credentials in an encrypted store, routes orders through isolated bridges, and never touches client money. Your broker remains your custodian. Always.

Credential ingress

TLS · HSTS-ready deployment
OAuth 2.0 / API-key flow
Trading scope only — no withdrawal permissions
IP allowlist (optional)
Zero password storage
AES-GCM Store

Execution egress

Dedicated broker bridge
Workspace-scoped key context
Signed + timestamped
Anomaly — auto-pause
Full audit trail
Trust controls

Built for traders who read the docs.

Every control below is on by default. No asterisks, no enterprise-only paywalls for the basics.

AES-GCM at rest

Sensitive credentials use app-managed AES-GCM encryption. KMS-backed rotation is tracked as production hardening.

TLS in transit

HTTPS-ready deployment, secure cookies, HSTS configuration and legacy TLS refusal are part of the production profile.

Risk engine on by default

Daily DD cap, per-trade risk %, symbol whitelist, news-event blocker.

Audit trail

Critical account, billing, role and trading actions write structured audit events for operator review.

Tenant isolation

Workspace-scoped RBAC and server-side query guards are in place; DB-level hardening remains a tracked launch gate.

Circuit breakers

Rate-limits per source, per broker, per account. Auto-pause on anomaly.

EU-first readiness

EU deployment, DPA/subprocessor review and SCC evidence are handled as legal readiness work before launch.

Compliance roadmap

Where we are, where we're going.

We're small, we're honest about it. Here's every compliance & audit milestone — on the record.

Q2 2026
Control inventory

Internal controls, evidence owners and readiness gaps documented before external audit.

Q3 2026
External readiness review

Independent review to confirm whether audit evidence is complete enough to start certification work.

TBD
SOC 2 Type I

Unavailable until an independent auditor issues a report.

TBD
ISO 27001

Certification remains unavailable until stage audits are completed.

Live status

Operations, in public.

The production status surface is wired as a launch gate; live telemetry is published once the deployment environment is connected.

Router core

Last incident: 42 days ago

Tracked
MT4/5 bridge

Last incident: 18 days ago

Tracked
cTrader bridge

No incidents 90d

Tracked
AI parser

Last incident: 7 days ago

Tracked
Credential encryption

KMS hardening pending

Tracked
Dashboard

Last incident: 3 days ago

Tracked
90-day readiness
Evidence-backed uptime is published after launch
Pending

Security questionnaire?

We share the current security questionnaire, control inventory and draft DPA on request. SOC 2, pen-test and subprocessor evidence are marked pending until externally validated.