Skip to content
PraxAlphaby CloudPrax

Security

Built to keep your account under your control

Your broker credentials remain with your broker. PraxAlpha connects through authorized broker APIs.

Your account

Access and credentials

HTTPS everywhere

All traffic to the site, the app and the API is served over TLS with HSTS.

Two-factor authentication

TOTP-based 2FA with any standard authenticator app protects your PraxAlpha login.

Encrypted broker tokens

Kite access tokens are encrypted at rest with AES-GCM and are only decrypted in memory when needed.

No Zerodha credentials stored

You log in to Zerodha on Zerodha's own page. PraxAlpha never sees or stores your Zerodha password, PIN or TOTP.

Login history

See when and from where your account was accessed.

Audit logs

Security-relevant and trading actions such as settings changes, strategy toggles and orders are recorded.

Infrastructure

How the platform is run

Secrets outside source code

Keys and credentials are injected at deploy time and are never committed to the code repository.

Rate limiting

Authentication and public endpoints are rate limited to slow down brute-force and abuse.

Firewall

The server exposes only the ports it needs. Internal services such as the database are not reachable from the internet.

Trading safeguards

Controls on every order

Risk engine is the only path to orders

Strategies cannot place orders directly. Every order is validated against your limits first.

Daily limits

When your daily loss limit or profit target is reached, new entries are blocked for the rest of the day.

Automatic square-off

Open intraday positions are squared off automatically at 15:10 IST.

Reporting a security issue

If you believe you have found a vulnerability, please email support@praxalpha.com with details. Please do not test against other users' accounts.