Paper-only onboarding
Personal API keys are accepted only for supported paper accounts. Live accounts use the approved OAuth authorization path.
Security
Cataldex is built to limit what it can access, protect saved credentials, and keep each member's data separate.
Personal API keys are accepted only for supported paper accounts. Live accounts use the approved OAuth authorization path.
Paper credentials and OAuth access tokens are encrypted with a server key kept separate from the member database.
Passwords are salted and hashed. Login sessions are random, expire, and are stored only as hashes.
Members can only load records that belong to their own account. Administrative tools use a separate protected role.
Brokerage connections request only the supported permissions and can be removed from Cataldex or revoked through the provider.
System health, trade decisions, orders, and fills are recorded so problems can be found and reviewed.
Security posture
Cataldex does not claim SOC 2 certification or perfect protection. Production operations use HTTPS, secret rotation, backups, monitoring, incident procedures, and continued security testing. Live brokerage access remains subject to provider approval and account eligibility.