Skip to main content

Security and privacy

What Quanify holds, what it never holds, and the controls you have over both.

Your broker credentials

Connections are made by signing in at the broker, not at Quanify. You are redirected to Tradovate's own page, you authorise Quanify there, and you come back. Quanify never sees or stores your broker password. The engine keeps the access token the broker issues, encrypted at rest, and uses it only to read your accounts and place the orders you have routed.

Because the authorisation lives at the broker, you can revoke it from the broker's side at any time, independently of anything you do in Quanify. Deleting the connection from Connections clears the routing that pointed at it from this side.

Your webhook tokens

Each strategy you create has its own webhook URL, and the token in that URL is a credential. Anyone holding it can send signals to that strategy.

  • Do not paste a webhook URL into a screenshot, a public chart, a shared repository or a support message.
  • Set a webhook password on any strategy that trades a funded account, so the token alone is not enough.
  • Use one strategy per signal source, so a token you need to retire can be retired on its own.
  • If a token may have leaked, delete the strategy and create a new one. The replacement gets a new token; re-point your alert at it.

What Quanify can and cannot do with your accounts

  • It places and closes orders on the sub-accounts you have explicitly routed and powered on, or that you have put in a copy group and switched on. Nothing else.
  • It cannot move funds. There is no Quanify brokerage, no wallet and no transfer.
  • It will not flatten a position on its own. Every control that closes a position is one you press and confirm.
  • Fills only ever clone to accounts you own. The ownership gate is checked on every fan-out, is not configurable, and cannot be switched off.

Hiding what is on screen

Hide ID in Connections masks account identifiers and balances. Use it before a screen share, a screenshot or a session in a public place. It is a display control only. It changes nothing about what is connected or routed.

Signing in

Accounts are created with an email address and a 6-digit code sent to it, or with Google sign-in where it is offered. Passwords must be at least 10 characters with letters and numbers, and are stored as salted hashes. A forgotten password is reset from the sign-in page by a code sent to your email. Your session covers the workspace, the public site and this documentation, so you are not asked to sign in again as you move between them, and signing out ends it.

Your password can be changed from the Security card in Settings. It asks for your current password first. Changing it does not interrupt anything that is routed: the engine holds the routing, not your browser session.

Linking Discord

Connecting Discord from Settings asks for exactly two things: who you are, and permission to add you to the Quanify server. Nothing about your messages, your other servers or your email. One Discord account links to one Quanify account, the role you receive follows your plan, and Disconnect unlinks immediately.

Resetting your workspace

Reset account in Settings wipes what you have configured and leaves you with a clean workspace. It removes your broker connections and sub-accounts, clears your strategy library and anything you added from the published library, tears down your Copy Trader group and its followers, and resets layout, theme and tab preferences.

Your login, your email address and your subscription stay. The action cannot be undone, and it asks you to confirm.

What it does not do: it does not close a single position. If you are holding something when you reset, you are still holding it afterwards, at your broker, where you can close it.

What is not in the product

Quanify does not currently offer two-factor authentication, an active-sessions device list, or user-issued API keys. If you have seen any of those described somewhere, they are not features you have. This page will change when they exist.

Reporting something

If you believe an account has been accessed without your permission, revoke the broker authorisation at your broker first (that stops orders at the source regardless of anything else), then mute the affected accounts, change your password, and get in touch through Discord from the Help tab.