Security

Security & Logic Isolation

Algovex keeps your account and strategy logic safe with server-side authorization, encryption in transit and at rest, and two-factor authentication.

Server-side authorization

Every sensitive action is authorized on the server against your session — the browser can never grant itself access.

Server-enforced

Encryption in transit & at rest

All traffic is served over TLS and internal service traffic is encrypted; stored secrets are encrypted at rest with AES-256-GCM.

TLS + AES-256-GCM

Two-factor authentication

Accounts can enable 2FA (authenticator app or email codes) for an extra layer on sign-in and sensitive actions.

TOTP / email 2FA

Implemented controls

Concrete hardening measures in the current Algovex stack, designed to prevent token leakage and reduce abuse:

Secure, server-side sessions

Sessions use secure, server-side cookies with refresh rotation. Tokens are never returned to the browser as JSON and are stored hashed.

httpOnly cookies + rotation

CSRF protection (same-origin)

State-changing requests are verified to originate from Algovex itself; sign-in and account endpoints get the same protection.

Same-origin verification

Content Security Policy

A per-request Content Security Policy limits what can execute in the browser, reducing the impact of injection attacks.

Strict CSP

Rate limiting

Authentication and other sensitive endpoints are rate-limited to reduce brute-force and automated abuse.

Abuse controls

Hosting & privacy

Algovex is hosted in the EU under GDPR. Internal services are network-isolated and internal traffic is encrypted, and sign-in metadata is recorded to support investigation and incident response.
© 2026 tacticx Development GmbH. All rights reserved.