← Back to MarketPilot

Security

Broker credentials

Your API keys and daily session tokens are encrypted at rest (Fernet/AES) with a key stored outside the web root. Your broker PIN, password and TOTP are never stored — they pass through to the broker's official login endpoint only at the moment you log in.

What connected accounts can and cannot do

ICICI Direct connection is read-only by default; real order placement additionally requires your typed confirmation, a daily spending cap you control, and (per ICICI policy) a whitelisted static IP. Angel One is used primarily as a market-data feed.

Application security

Your part

Use a unique password, never share screenshots containing API keys, and regenerate any key you suspect is exposed (both brokers let you do this instantly in their developer portals).

MarketPilot is an educational platform, not a SEBI-registered investment adviser. Nothing on this site is investment advice.