Security by default

Protect the account before protecting the convenience

TickerHoof combines verified identities, MFA, revocable sessions and restricted integrations to reduce avoidable account risk.

Strong password storage

Passwords are one-way hashed using Argon2id. TickerHoof cannot retrieve or email your original password.

Multi-factor authentication

Authenticator-app codes and recovery codes add a second layer beyond the password.

Verified email

Accounts must prove control of their email address before normal authenticated access is completed.

Session management

Active sessions can be inspected and revoked. Sensitive account changes can invalidate existing sessions.

Encrypted provider secrets

Sensitive OAuth credentials are encrypted at rest using application-managed cryptographic keys.

Security monitoring

Login, account and administrative events can be recorded for investigation and user notification.

Alpaca integration

Portfolio visibility without order authority

The TickerHoof Alpaca connection is designed for read-only account and position retrieval. The application does not use it to place, cancel or modify trades.

  • OAuth avoids asking you to type brokerage credentials into TickerHoof.
  • Connection tokens are stored encrypted.
  • Synchronisation errors do not trigger trading actions.
  • You can disconnect the integration from account settings.
Permission boundary

What the connection can do

Read

Retrieve permitted account, balance and position information.

Do not request

Trade execution, withdrawals, transfers or changes to brokerage security settings.

Payments

Billing is separated from research

Stripe is used for subscription checkout and billing management. The intended design keeps full payment-card details outside TickerHoof's application database.

  • Server-side webhook verification before billing events are trusted.
  • Provider event IDs are retained to prevent duplicate processing.
  • Subscription access is derived from recorded entitlement state.

Hosted billing flow

Checkout and billing-portal sessions are created server-side and returned only to the authenticated user.

Your part matters

How to secure your account

Use a unique password

Do not reuse a password from email, banking, brokerage or another website.

Protect recovery codes

Store recovery codes offline or in a trusted password manager, separate from your authenticator device.

Review login alerts

Act promptly on an unexpected login, email change or integration connection notification.

Report a concern

Think something is wrong?

Do not include passwords, MFA codes, recovery codes or brokerage secrets in an email. Contact the security address with a clear description and the affected page.

Contact security