Skip to main content

Verified practices, no certification theater

Your record is private infrastructure—not marketing inventory.

TraderLeveling separates account data by tenant, keeps desktop connection credentials local, limits analytics to pseudonymous product events, and gives users export and deletion controls.

Private by architectureTenant-isolated hosted dataLocal Terminal credentialsExplicit AI boundaryUser export and deletion

Implemented controls

What the current architecture actually does.

No SOC 2, ISO 27001, PCI, brokerage-integration, or uptime certification is claimed on this page.

01

Authentication

Passwords are stored as salted hashes. Session cookies are HttpOnly and SameSite=Lax, with Secure enabled in the hosted authenticated service. Email verification and password-reset links are signed and expire.

02

Tenant separation

Hosted application data uses PostgreSQL row-level security with fail-closed tenant policies. Access is resolved from the authenticated account, not from a client-provided account identifier.

03

Abuse controls

Credential actions are rate-limited, production startup rejects insecure secret defaults, and sensitive integrations fail closed when required encryption configuration is absent.

04

Terminal credentials

Credentials entered for desktop data connections are stored locally on your device and are not transmitted to TraderLeveling. The live feed is read and analyzed locally.

05

Transport and storage

The hosted service uses TLS in transit. Supported hosted broker credentials are encrypted at rest; the service does not store plaintext account passwords or full payment card numbers.

06

User control

Users can export journal records, disconnect integrations, delete individual content, and permanently delete their account from settings after password confirmation.

Know which layer is speaking

Numbers, narration, user content, and external data stay distinguishable.

Deterministic calculations

P&L, account risk, distributions, grades, and detection events are computed from available records. They can still be incomplete if the input is incomplete.

AI narration

Relevant user content is sent to Anthropic only when an AI feature is used. AI interprets and organizes; it does not invent the quantitative performance record.

User-entered content

Trades, journal entries, rules, setup definitions, annotations, and derived methodology remain the user’s content and are not used to coach another user.

Third-party data

Connected trade and fill data can populate the record. Live market data from user connections is processed per session and not added to TraderLeveling datasets.

Retention and control

Keep the record while the account is active. Delete it when it should end.

User content is retained while the account is active or until the user deletes it. Account deletion is completed within 30 days except for legally required records; encrypted backups can remain on normal rotation for up to 90 days. Pseudonymous product analytics are retained up to 12 months. See the policy for the complete table.

Review exact retention periods