How we keep your journal safe.

Last updated 7 October 2026

Your trading journal is personal. Here is how SteadyPnL protects it: first in plain words, then in technical detail for anyone who wants to check our work.

1. No passwords to steal

You sign in with a 6-digit code (or a one-time link) sent to your email. There is no password to guess, reuse or leak, and nothing for a phishing page to collect.

Technical detail
  • Each link carries a 256-bit token from a cryptographically secure random generator.
  • We store only a SHA-256 fingerprint of the token, never the token itself.
  • A link expires after 20 minutes and is burned the moment it is used, in a single atomic check.
  • Opening the link shows a confirm button, so email security scanners that pre-open links cannot use it up or sign in.
  • Each code is 6 digits from the same secure generator, stored only as a hash, valid for 10 minutes and usable once. After 5 wrong tries it is burned and a new one must be requested.
  • Using the code cancels the link, and using the link cancels the code.
  • Sign-in requests are rate-limited per email address and per network.

2. Sessions that scripts cannot read

Once you are in, you stay signed in on that device, and the session key it holds cannot be read by scripts on web pages. Signing out ends it where it matters: on our side.

Technical detail
  • 256-bit random session ID, stored server-side only as a SHA-256 hash, so even a copy of our database could not sign anyone in.
  • Cookie flags: Secure, HttpOnly, SameSite=Lax.
  • Sessions last 60 days and renew automatically while you use the app. Signing out deletes the session record immediately, and expired sessions are purged.

3. Encrypted in transit and at rest

Everything between your device and SteadyPnL travels over an encrypted connection, and your journal is encrypted where it is stored, including backups.

Technical detail
  • HTTPS only: plain HTTP is redirected, HTTP Strict Transport Security (HSTS) is on, and only TLS 1.2 or newer is accepted, with TLS 1.3 preferred.
  • Traffic between our application layer and the database is also encrypted with TLS.
  • Stored data, including live databases, inactive databases and metadata, is encrypted at rest with AES-256 in GCM mode.
  • Your journal lives in a database located in Western Europe.

4. No server for anyone to break into

SteadyPnL does not run on a traditional server that sits on the internet waiting to be attacked. The app runs as lightweight code inside isolated sandboxes spread across a global network.

Technical detail
  • Code runs in isolated sandboxes on a global edge network, separated from other software on the same hardware. There are no machines of ours exposed to the internet: no open ports and no remote shell access to attack.
  • Every database query is parameterised (no SQL built from text you type) and scoped to the signed-in account, so one account can never read another account's records.
  • Request size and batch limits protect the service from oversized or malformed uploads.

5. Protected against attacks and floods

Every request passes through a protective network layer before it reaches the app. Attempts to overwhelm the site are absorbed and filtered automatically.

Technical detail
  • Always-on, unmetered DDoS mitigation at the network and application layers (L3 to L7).
  • Requests that change data are checked for the correct origin, which blocks cross-site request forgery (CSRF).
  • Rate limits on sign-in, plus bot traps on public forms.

6. A hardened browser experience

Our pages tell your browser exactly what they are allowed to do, so injected code, look-alike framing and data leaks through links are blocked by the browser itself.

Technical detail
  • A Content Security Policy that only allows scripts, styles, fonts and connections from steadypnl.com, and no plugins or embedded objects.
  • Framing is denied (frame-ancestors 'none' and X-Frame-Options: DENY), which stops clickjacking.
  • X-Content-Type-Options: nosniff, a same-origin referrer policy, and a permissions policy that switches off camera, microphone, location and payment APIs.
  • Cross-origin isolation of the app window (Cross-Origin-Opener-Policy: same-origin).

7. Nobody else on our pages

There are no ad networks, tracking pixels, analytics scripts, chat widgets or externally hosted fonts. Every file you load comes from steadypnl.com, so your visit is not reported to anyone.

Technical detail
  • Fonts are self-hosted and subset. No third-party script runs on any page.
  • We measure usage only as anonymous daily totals (for example, "12 days closed today"), with no cookie, no IP address and no user ID attached.

8. We hold less, so less can leak

The safest data is data we never have.

  • No broker or prop-firm logins. We never ask for your trading passwords or API keys. Trades come in from files you export or numbers you type.
  • No card numbers. When paid plans start, payments are handled entirely by a certified payment provider. Card details never touch our systems.
  • Screenshots stay on your device. Chart screenshots you attach are kept in your browser and are not uploaded.

9. Backups and recovery

If something ever went wrong, we can rewind your journal, and you can always keep your own copy.

Technical detail
  • Continuous point-in-time recovery: the database can be restored to any minute of at least the last 7 days.
  • One-click export of your full journal (JSON) and trades (CSV) from Accounts & rules, and restore from a backup file.

10. Emails you can trust

Our emails are signed, so your inbox can check they really come from SteadyPnL. We will never ask you for a password, a broker login or payment details by email.

Technical detail
  • Sent over encrypted connections and authenticated with DKIM and SPF for steadypnl.com.
  • Sign-in emails only ever link to https://steadypnl.com/auth. If a link points anywhere else, it is not from us. We will never ask you to read your code out to anyone.

Found a problem?

If you think you have found a security issue, email support@steadypnl.com with "Security" in the subject. Please give us a chance to fix it before sharing it publicly. We read every report.

See also our privacy policy and terms.