How VEXA protects your data

Encryption in transit and at rest, per-user access rules, how broker credentials are held, and the plain statement that VEXA does not sell your data.

Same on every platform Updated

What this does

This is what VEXA does to keep your account yours. It is a summary of section 7 of the VEXA Privacy Policy, with the broker-credential detail spelled out because that is what people actually ask about.

The measures in place

  • Encryption in transit and at rest. Traffic between your device and VEXA runs over TLS. Stored data is encrypted at rest.
  • Per-user access rules. Database security rules scope every read and write to the account that owns the record. Your data is not reachable from another user’s session.
  • Broker credentials are encrypted separately. API keys, OAuth tokens, exchange secrets and Interactive Brokers Flex tokens are encrypted with AES-256-GCM using a key held outside the database, and are decrypted only inside VEXA’s servers when a sync runs.
  • No broker passwords. VEXA connects with API keys, OAuth tokens or uploaded files. It never asks for and never stores the password to your brokerage.
  • Credentials never leave in an export. Every credential-bearing field is stripped out of your data export before the file is written, because that file is meant to be shared with you and could end up anywhere.
  • Server-side processing of sensitive work. Score calculation, baseline maths and broker sync run on VEXA’s servers, not in the app on your device.
  • Session management. Sign-in tokens expire and sessions are managed automatically.
  • Regular security audits and vulnerability assessments.

What VEXA does not do with your data

  • It does not sell your personal information. That is stated in the Privacy Policy, and repeated for California residents under CCPA.
  • It does not sell, rent or lease your health or biometric data to any third party. The policy calls that an absolute commitment.
  • It does not use your data to train general-purpose AI models. See How VEXA uses AI with your data.
  • Individual trading data is not shared publicly without your explicit action, such as opting into a leaderboard.

One caveat

As the Privacy Policy states: no method of transmission over the internet or electronic storage is completely secure, and VEXA cannot guarantee absolute security. What VEXA can do is the list above.

What you can do

  • Use a strong, unique password, or sign in with Google or Apple.
  • Create broker API keys with reading enabled and trading and withdrawal switched off. VEXA’s own setup instructions tell you to do exactly that. See What VEXA can do with your broker connection.
  • Store your export file somewhere private. It is plain JSON that anyone who opens it can read, and once it is on your device its safety is on you.
  • Remove broker connections you no longer use, and revoke the key at your broker as well.

Where the data lives

VEXA runs on Google Cloud infrastructure and your information may be processed in countries other than where you live, including the United States. The Privacy Policy covers international transfers in section 14 and names the safeguards used, including standard contractual clauses.

What you should see

Nothing, if this is working. The one place it becomes visible is your export file: open it and search for your broker’s API key. It will not be there.

If it doesn’t work

  • You think your account has been accessed by someone else. Change your password, remove any broker connection you do not recognise, and email support@vexatrade.ai.
  • You found something that looks like a security problem. Report it to support@vexatrade.ai rather than posting it publicly.

Related

Still stuck? Email support@vexatrade.ai.