Security & Trust

Your security is our top priority. Here's how we protect you.

🔐 Signed Communications

Every request between your EA and our server is signed with HMAC-SHA256. This means no one can intercept, modify, or replay commands. Each request includes a unique nonce and timestamp — used once, then rejected.

🏗️ Per-Account Isolation

Each customer's data is stored in a completely separate bucket, identified by their unique token. Customer A cannot see, access, or interact with Customer B's data — even if they share the same server infrastructure.

🚫 No Access to Your Funds

Falcon AI NEVER has access to your trading account funds. The EA runs on YOUR computer, connected to YOUR broker. We cannot withdraw, deposit, or transfer money from your account. We only send trading signals — your broker executes them.

🛡️ Admin Access Controls

Admin operations require a separate master token with brute-force protection (automatic lockout after failed attempts). All admin actions are logged in an immutable audit trail.

📁 Private File Storage

Files shared in chat are stored in private Google Drive folders — one per customer. No public links are ever generated. Files are served through an authenticated proxy that verifies your identity before delivering content.

🔄 Data Export & Deletion

You can export all your data at any time from your dashboard. You can also request complete deletion of your data by contacting support. We respect your right to control your information.

🔒

HTTPS Encrypted

HMAC Signed

🏦

No Fund Access

👤

Data Isolated

📋

Audit Logged

📥

Data Exportable