Security · posture v3

We hold the smallest possible permission. Always.

DyadScalp is a decision and execution terminal. We connect to your broker with the minimum scope required to place and manage orders — never to withdraw funds, never to modify your bank mandates.

Control
Broker scopes we request

Read holdings · Read positions · Place/modify/cancel orders. We do NOT request fund-withdrawal, profile-edit, or bank-mandate scopes. If your broker's OAuth screen asks for more, refuse and tell us.

Control
Token storage

Broker access tokens are encrypted at rest using AES-256-GCM with per-tenant keys held in Lovable Cloud's secret store. Tokens are never logged, never sent to analytics, and rotated on every session boundary.

Control
Where your data lives

Order history, signals, and audit ledger live in a Postgres database in the ap-south-1 region, with row-level security scoped to your user_id. Backups are encrypted and retained 30 days.

Control
What we will never do

Read your email. Read your trades from any broker you haven't connected. Sell aggregated trade data to a third party. Auto-place orders without an explicit per-trade confirmation.

Reporting a vulnerability

If you believe you've found a security issue, email security@dyadscalp.app. We respond within 48 hours and publish a postmortem for any verified issue on the changelog.

Be skeptical, always. No trading product should be trusted on marketing copy alone. Review the methodology, inspect the track-record ledger, and start in paper mode before sizing in.