Security at CrossTrade
How we protect your account, your broker connections, and your trading data, what we ask of you in return, and how to report a problem.
Effective Date: September 13, 2026 | Last Updated: September 13, 2026
1. How Broker Credentials Are Handled
The most sensitive thing we touch is the authorization that lets us act on your brokerage account. How that works depends on which broker you connect, and the difference matters.
NinjaTrader 8
The CrossTrade NT8 Add-on runs inside NinjaTrader on a machine you control, whether that is your own computer or a VPS. Your NinjaTrader brokerage login never reaches us. It stays on that machine, held by NinjaTrader itself. What travels between the add-on and our service is instruction and result traffic addressed to your account, over an encrypted connection.
Tradovate
Connecting Tradovate uses Tradovate's own OAuth sign-in. We never receive or store your Tradovate password. What we receive and store are access and refresh tokens scoped to the accounts you authorized. Those tokens let us act on those accounts until you revoke them, which you can do at any time from your CrossTrade settings or from Tradovate directly. Revocation takes effect immediately for new requests.
Your CrossTrade password and secret key
CrossTrade account passwords are stored as one-way bcrypt hashes with a per-password salt. We cannot read your password, and neither can anyone who obtains a copy of our database. Your Customer Secret Key, which authenticates inbound webhook alerts, functions as a credential and should be protected the same way. If you believe it has been exposed, rotate it from your account settings immediately.
2. Encryption
In transit. All traffic between your browser, the mobile app, the NT8 Add-on, and our services runs over TLS. Our webhook endpoints accept HTTPS only. Traffic between our own services and your broker's API is likewise encrypted in transit.
At rest. Our databases and file storage run on managed infrastructure with encryption at rest enabled at the storage layer, so the underlying disks and backups are encrypted.
Integrity of inbound messages. Webhook traffic we receive from payment and partner systems is verified against a shared signing secret before it is acted on, and requests that fail signature verification are rejected. The same signed-payload approach is used for service-to-service calls within our own platform.
3. Platform Safeguards
- Rate limiting. Authentication, webhook intake, API access, and support chat are rate limited per account to blunt credential stuffing, abuse, and runaway automation.
- Bot and abuse protection. Public forms and sign-up flows are protected by a challenge service to reduce automated abuse.
- Destructive query guard. Our application layer refuses to issue destructive database statements. Schema changes are applied deliberately by a human and are never executed by application code or by an automated process.
- Scoped API access. Where you issue API credentials or authorize an AI client over MCP, access is scoped to the surface presented at authorization time and can be revoked by you at any time.
- Separation of duties. Access to production systems is limited to the people who need it to operate the service.
4. What We Ask of You
A meaningful share of account compromise in this industry starts on the customer's side, not the provider's. The following are not formalities:
- Use a unique password for CrossTrade that you do not use anywhere else, and use a password manager.
- Never share your Customer Secret Key or webhook URL. Anyone who has them can submit alerts that place orders in your account. Treat a webhook URL like a password, not like a link.
- Do not post screenshots containing your secret key, webhook URL, account numbers, or API credentials in Discord, forums, support threads, or social media. Redact before you post.
- Secure the machine running the NT8 Add-on. If it is a VPS, use a strong unique password and keep remote access locked down. Anyone with access to that machine has access to your trading platform.
- Revoke what you are not using. Disconnect brokers, API credentials, and AI clients you no longer need.
- Use your broker's own protections alongside ours, including native protective orders and any account-level controls your broker or funding program offers.
5. Reporting a Vulnerability
If you believe you have found a security vulnerability in CrossTrade, please report it to [email protected]. We read every report and will confirm receipt.
Please include enough detail to reproduce the issue, including the affected endpoint or page and the steps you took.
While testing, please do not:
- Access, modify, or extract another user's account, trading data, or broker credentials.
- Place, modify, or cancel live orders on any account you do not personally own.
- Run denial of service tests, spam our systems, or degrade the service for other users.
- Use social engineering against our staff, our customers, or our vendors.
If you find a way to reach another user's data, stop, do not retrieve more than the minimum needed to demonstrate the issue, and tell us. We will not pursue legal action against researchers who follow this guidance and report in good faith. Our machine-readable contact is published at /.well-known/security.txt.
6. If Something Goes Wrong
If we become aware of a breach affecting your personal information, we will notify affected users and the relevant authorities as required by applicable law, including the timelines described in Section 6.4 of our Privacy Policy and Section 8A of our Terms of Service. Our notice will describe what happened, what information was involved, and what you should do.
If you believe your CrossTrade account has been compromised, act first and tell us second: change your password, rotate your Customer Secret Key, revoke connected brokers and AI clients from your account settings, and then write to [email protected]. If you believe your brokerage account is affected, contact your broker directly, since only they can halt activity on it.
7. What We Do Not Claim
We would rather tell you where we stand than imply more than is true.
CrossTrade does not currently hold a SOC 2, ISO 27001, or PCI DSS certification. We do not process or store payment card numbers; card payments are handled entirely by our payment processor, which maintains its own PCI compliance. No security program eliminates risk, and as our Terms of Service state, we cannot guarantee that our systems will never be compromised.
If you are evaluating CrossTrade for an organization and need a security questionnaire completed, a named subprocessor list, or a data processing agreement, write to [email protected] and we will work through it with you.
8. Contact
Security reports and questions: [email protected]
Privacy and data rights: [email protected]
General support: [email protected]
CrossTrade LLC, a Wyoming limited liability company.