Security – EdgeHabit

Last updated: 28 July 2026

We are committed to protecting the confidentiality, integrity and availability of your personal information and trading journal data. This Security page is a human‑readable summary of the data‑security measures described in our Privacy Policy and Terms & Conditions. In case of any conflict, the Privacy Policy governs how we handle personal data.

1. Technical safeguards

We use reasonable administrative, technical and organisational safeguards designed to protect your data, which may include:

Encryption in transit (HTTPS/TLS) for data exchanged between your browser or app and our servers.

Encryption at rest for sensitive fields.

Access controls and authentication controls to restrict production data access to authorised personnel on a need‑to‑know basis.

Logging and monitoring of security‑relevant events, API usage and infrastructure health.

Backup procedures and incident‑response processes for recovery and investigation of security incidents.

We may update and improve these measures over time as security best practices, legal requirements and our infrastructure evolve.

2. Handling broker credentials and API keys

Public broker sync is currently coming soon. Do not send EdgeHabit your broker password, PIN, MPIN, OTP, TOTP code, TOTP seed, API key, or API secret unless a future broker-specific connection screen expressly confirms that the integration is enabled and the method is permitted.

For any future approved integration, the screen will disclose what EdgeHabit receives and why. Any retained broker-issued token or broker-permitted credential will be encrypted in transit and encrypted at rest, will be scoped to that user, and will be removed or rendered unusable when the connection is deleted, subject to legal and short-lived operational retention.

A broker name or logo does not imply support, partnership, affiliation, approval, or endorsement. EdgeHabit will not advertise a broker connection as available until it is enabled through a broker-permitted method.

3. Internal access and organisational safeguards

EdgeHabit personnel, contractors or support providers may access user data only where reasonably needed for support, debugging, security investigation, abuse prevention, legal compliance, product maintenance or billing and account administration. Access is limited based on role and necessity and may be logged where technically supported.

We require confidentiality obligations from team members and service providers who may have access to personal data, and we aim to work only with vendors that implement appropriate security measures.

4. Third‑party providers and infrastructure

We use reputable third‑party providers for cloud hosting, databases, storage, authentication, payments, email, monitoring, analytics, customer support tools, AI infrastructure and security/incident response. These providers may process data only as needed to provide services to us, subject to contractual and technical safeguards where applicable.

Your data may be processed in India or other countries where our service providers operate, with reasonable safeguards consistent with applicable law and service requirements.

5. No absolute security guarantee and your responsibilities

No method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security. By using EdgeHabit, you understand and accept this residual risk.

You are responsible for keeping your EdgeHabit login secure, using strong passwords, enabling two‑factor authentication where available, keeping your devices and email accounts secure, and promptly notifying us if you suspect unauthorised access to your EdgeHabit or broker accounts.