1. Broker connections
Charles Schwab connects through read-only OAuth. You authorize the connection on Schwab’s own login screen — MyTradeLens never sees or stores your Schwab password. The resulting access token can only read the order history you approved; it cannot place trades, move funds, or withdraw.
Interactive Brokers connects via a read-only Flex Query you configure and authorize yourself. Moomoo data comes from a CSV export you upload — there is no standing connection to revoke because none is made.
2. Account security
- Passwords are hashed with bcrypt — we never store them in plain text, and we never see your broker passwords at all.
- Optional two-factor authentication (TOTP) can be enabled from your Profile page for an extra sign-in step.
- Sign-in and password-reset endpoints are rate-limited to slow down credential-stuffing and brute-force attempts.
3. Data in transit & at rest
All traffic to MyTradeLens is served over HTTPS. Sessions are issued as httpOnly cookies with the Secure and SameSite attributes set in production, so they can’t be read by page scripts or replayed cross-site. Broker OAuth tokens are encrypted at rest in our database, separate from the account row they belong to.
4. Controls you have
- Revoke a broker connection at any time — from MyTradeLens, or directly from the broker’s own security settings.
- Delete your account from the Profile page, which purges your rows across every MyTradeLens table, including cached broker data and tokens.
- Request an export or copy of your data by emailing support@mytradelens.com.
See the Privacy Policy for the full list of what we collect and why.
5. Reporting a vulnerability
If you believe you’ve found a security issue, please email support@mytradelens.com with details before disclosing it publicly. We read every report and will follow up.