Strategy and tradingTrust boundary
Privacy and security
Maintain the explicit excluded-data contract across desktop metadata, MCP, iOS auth, and the hosted trading surface.
Privacy and security — contract and behavior
- Desktop allow lists never include secrets, databases, transcripts, prompt stores, or recursive source trees.
- The iOS bundle contains only publishable client configuration and user-scoped session material.
- Service-role, model-router, market-provider, and trading execution credentials stay server-side.
- Logs and diagnostics avoid strategy contents, local paths beyond the selected root, auth tokens, and trading payloads.