Security
Built to keep your account under your control
Your broker credentials remain with your broker. PraxAlpha connects through authorized broker APIs.
Your account
Access and credentials
HTTPS everywhere
All traffic to the site, the app and the API is served over TLS with HSTS.
Two-factor authentication
TOTP-based 2FA with any standard authenticator app protects your PraxAlpha login.
Encrypted broker tokens
Kite access tokens are encrypted at rest with AES-GCM and are only decrypted in memory when needed.
No Zerodha credentials stored
You log in to Zerodha on Zerodha's own page. PraxAlpha never sees or stores your Zerodha password, PIN or TOTP.
Login history
See when and from where your account was accessed.
Audit logs
Security-relevant and trading actions such as settings changes, strategy toggles and orders are recorded.
Infrastructure
How the platform is run
Secrets outside source code
Keys and credentials are injected at deploy time and are never committed to the code repository.
Rate limiting
Authentication and public endpoints are rate limited to slow down brute-force and abuse.
Firewall
The server exposes only the ports it needs. Internal services such as the database are not reachable from the internet.
Trading safeguards
Controls on every order
Risk engine is the only path to orders
Strategies cannot place orders directly. Every order is validated against your limits first.
Daily limits
When your daily loss limit or profit target is reached, new entries are blocked for the rest of the day.
Automatic square-off
Open intraday positions are squared off automatically at 15:10 IST.
Reporting a security issue
If you believe you have found a vulnerability, please email support@praxalpha.com with details. Please do not test against other users' accounts.
