We use cookies to improve your experience.

Security at FlockTrade.

You trust us with your account, your journal and your payment details. Here is how we protect them, and how to reach us if you ever spot something.

01Data in transit and at rest

All traffic between your browser and FlockTrade is encrypted with TLS. Sensitive data is protected at rest on our infrastructure, and access to production systems is limited to the people who need it, over authenticated and logged channels.

02Account protection

Passwords are stored only as salted, one-way hashes, never in plain text, so nobody, including us, can read them. You can also sign in with Google or Discord and let those providers handle authentication. We recommend a unique, strong password and keeping your linked accounts secure.

03Payments

Subscription payments are handled by a PCI-DSS compliant payment processor. Your full card details are entered with the processor, not with us, and are never stored on FlockTrade servers. We only keep the subscription status and the records we need for billing.

04Infrastructure and monitoring

The platform runs on hardened, regularly patched infrastructure. We separate user content from application code, take routine backups, and monitor the service for errors and abuse so we can respond quickly when something looks wrong.

05Tenant isolation

FlockTrade supports white-label deployments. Each tenant's branding and configuration are isolated, and data access is scoped to the tenant it belongs to, so one community's data is never exposed to another.

06Your part

Security is shared. Use a strong, unique password, be careful with the devices you stay signed in on, and never share your account. Tell us right away if you think your account has been accessed without your permission.

07Responsible disclosure

If you believe you have found a security vulnerability, we want to hear from you. Email support@flocktrade.com with the subject "Security disclosure" and enough detail to reproduce the issue. Please give us a reasonable chance to fix it before disclosing it publicly, and do not access or alter data that is not yours. We are grateful to researchers who report issues responsibly.

08Questions

For anything else about security or privacy, see our Privacy Policy or reach us through the contact page.