Security
Security at EarlySignal
Security covers more than account access. EarlySignal also protects the integrity, provenance, and portability of the trading records used in your analysis.
Last updated: August 15, 2026
Account protection
New accounts require email verification. Passwords are hashed with Argon2id, and optional time-based one-time-password two-factor authentication includes recovery codes. You can revoke active sessions and reset account credentials from the application.
Application safeguards
EarlySignal uses a restrictive Content Security Policy, same-origin checks for state-changing requests, security-focused response headers, bounded input validation, and distributed rate limiting in production. Sensitive operations are re-authenticated where appropriate and security-relevant activity is recorded in an audit trail.
Trading-record integrity
Financial values use fixed-precision decimal storage. Execution changes recompute trade aggregates in the same transaction, and database constraints protect prices, quantities, trade lifecycles, and tenant ownership boundaries.
Smart Import previews the exact reconcile plan before approval. Stable execution identities and source lineage prevent proven duplicates, while changed broker records stop as correction conflicts instead of being silently overwritten. Import commits are atomic, and eligible completed imports can be rolled back.
Smart Import and AI
Depending on the active importer mode, structural headers and a bounded, redacted sample of trading values may be sent to the configured AI provider to map an unfamiliar schema. Provider storage is requested to be disabled. The model returns mapping metadata only; EarlySignal parses and validates every execution locally. See the Privacy Policy for the complete data-sharing boundary.
Data control and recovery
You can export trading data in CSV or JSON, download a complete account archive, archive and restore trades, and permanently delete your account. Production recovery relies on protected database backups and a documented restore process; user exports remain available for portability.
Report a security issue
If you believe you found a vulnerability or account-security issue, email support@earlysignal.co with enough detail for the issue to be reproduced. Do not include passwords, recovery codes, or other secrets in the report.

