Strong password storage
Passwords are one-way hashed using Argon2id. TickerHoof cannot retrieve or email your original password.
TickerHoof combines verified identities, MFA, revocable sessions and restricted integrations to reduce avoidable account risk.
Passwords are one-way hashed using Argon2id. TickerHoof cannot retrieve or email your original password.
Authenticator-app codes and recovery codes add a second layer beyond the password.
Accounts must prove control of their email address before normal authenticated access is completed.
Active sessions can be inspected and revoked. Sensitive account changes can invalidate existing sessions.
Sensitive OAuth credentials are encrypted at rest using application-managed cryptographic keys.
Login, account and administrative events can be recorded for investigation and user notification.
The TickerHoof Alpaca connection is designed for read-only account and position retrieval. The application does not use it to place, cancel or modify trades.
Retrieve permitted account, balance and position information.
Trade execution, withdrawals, transfers or changes to brokerage security settings.
Stripe is used for subscription checkout and billing management. The intended design keeps full payment-card details outside TickerHoof's application database.
Checkout and billing-portal sessions are created server-side and returned only to the authenticated user.
Do not reuse a password from email, banking, brokerage or another website.
Store recovery codes offline or in a trusted password manager, separate from your authenticator device.
Act promptly on an unexpected login, email change or integration connection notification.
Do not include passwords, MFA codes, recovery codes or brokerage secrets in an email. Contact the security address with a clear description and the affected page.
Contact security