How we protect your account and your data.
ObviousTrades reads your positions and transaction history to analyze them. It does not place trades, move funds, or make withdrawals. Where your broker offers read-only authorization, connections use it, and you can disconnect a brokerage at any time.
All traffic is encrypted in transit with TLS. Sensitive data such as brokerage access tokens is encrypted at rest.
Passwords are stored only as salted scrypt hashes, never in plain text, and new passwords are screened against known data breaches without ever leaving our servers. Two-factor authentication with any authenticator app is available on every account, with single-use recovery codes. Signing in from an unrecognized device requires a one-time code sent to your email. New accounts require email verification, and sign-up is rate limited.
Your account page lists every signed-in device with its last activity. You can sign out any device, or everywhere at once, and changing your password signs out all other devices automatically.
Payments are processed by Stripe on Stripe-hosted pages. Card numbers never touch our servers.
Every change to an account is recorded in an internal audit log, and your account page shows you its recent security activity.
Data is backed up on a nightly schedule to offsite storage kept separate from the primary server.
Administrative access to our servers is restricted to a private network, and the server firewall denies public administrative access.
Your brokerage connection is read-only and can be removed whenever you choose. You can export your data at any time, and delete your account yourself from your account page: deletion runs after a 7-day grace window you can cancel, then your data is permanently removed and any subscription is canceled. Idle sessions expire automatically.
Found a vulnerability? Email security@obvioustrades.com (machine-readable details at /.well-known/security.txt). We acknowledge reports within 72 hours and do not pursue action against good-faith research.