Security

Clear controls for connected trading.

Review account access, broker permissions, and product activity. Grant access carefully and check it often.

Account access

Use strong credentials and the authentication options available to your account. Astral limits protected product routes to authenticated sessions.

Scoped connections

Broker access follows the authorization and capabilities exposed by the connected broker or connection provider.

Visible activity

Orders, fills, alerts, and strategy state remain visible in the product so unexpected activity can be reviewed.

01

Broker authorization

Connected accounts use the broker or connection provider’s authorization flow. Review the scope presented during connection and revoke access from the relevant account when it is no longer needed.

02

Strategy responsibility

Backtests and paper results do not guarantee live outcomes. Review generated logic, sizing, order type, and protective conditions before allowing a strategy to interact with a live account.

03

Session and device hygiene

Protect the email, device, and browser used for Astral. Sign out of shared devices and report unexpected account or trading activity promptly.

04

Incident communication

If a security event requires user action, Astral will use the account and product communication channels available at that time.

Responsible disclosure

Found a security issue?

Email security@astral.trading with clear reproduction steps and the affected surface. Do not access data that is not yours, disrupt service, or perform social engineering.

Please allow time to investigate before public disclosure. Astral does not currently represent this page as a certification, independent audit report, or bug-bounty promise.

Keep rules and access visible.

Start with paper workflows. Connect a broker only after you review the strategy and permissions.