Security Practices
Last updated: 29 July 2026
This page is maintained by ProdigiAI to answer common security and privacy questions about MyTradeDesk. It describes the controls we have enabled today. It is not an audit report, a certification, or independent verification by any third party.
1. Shared responsibility
- Our hosting platform provides the managed database, authentication service, object storage and TLS termination, along with encryption in transit and at rest and platform-level backups.
- ProdigiAI is responsible for the application: access rules, data handling, retention, vendor selection and incident response.
- You are responsible for your password strength, keeping your login device secure, and what you choose to publish through share links or a public profile.
2. Access and authentication
- Email + password and Google sign-in, handled by our managed authentication service.
- Passwords are stored only as salted hashes. We never see or store your plaintext password.
- Every table holding your data is protected by row-level access rules scoped to your account, enforced by the database itself rather than by application code alone.
- Administrative actions are gated by a server-side role check. Roles live in a dedicated table and are never read from the browser as a source of truth.
3. Data in transit and at rest
All traffic to https://mytradedesk.in is served over HTTPS/TLS. Application data and uploaded attachments are encrypted at rest by the hosting platform. We do not offer end-to-end encryption — data is decrypted server-side so the app can compute your analytics.
4. Payments
Card, UPI and net-banking details are collected and processed entirely by Razorpay. They never reach our servers. We store only the payment reference, amount, status and the billing details you enter, and every payment is verified server-side before Pro access is granted.
5. Retention
- Trading data, journal entries and attachments: retained until you delete them or close your account.
- Deleted accounts: personal and trading data erased within 7 days of the request.
- Payment and invoice records: retained for 8 years as required by Indian tax law.
- Security, audit and error logs: retained for up to 180 days.
6. Vulnerability disclosure
If you believe you have found a security issue, email support@mytradedesk.in with the subject Security disclosure. Please include reproduction steps and give us a reasonable period to remediate before any public disclosure. We do not currently run a paid bug-bounty programme, but we will credit reporters who ask to be credited.
Please do not run automated scanners against production, access accounts that are not yours, or degrade the service for other users while testing.
7. Incident response and breach notification
- We triage suspected incidents on receipt and contain before we investigate.
- Where an incident is reportable under the CERT-In Directions of 28 April 2022, we intend to report it to CERT-In within 6 hours of becoming aware of it.
- Where a personal data breach occurs, we will notify each affected user and the Data Protection Board of India as required by the Digital Personal Data Protection Act, 2023, describing what happened, what data was involved, and what you should do.
- Security event logs, including timestamps, IP address and user agent, are retained to support investigation.
8. What we do not claim
We do not claim SOC 2, ISO 27001, PCI-DSS or any other certification, and we do not claim that the service is free of vulnerabilities. Where this page describes a platform capability, that is a description of a feature we have enabled, not an assurance issued by the platform provider or by any auditor.
9. Security contact
Varun Chatlani, Grievance Officer & Data Protection Officer
ProdigiAI, Mumbai, Maharashtra, India
Email: varun@prodigiai.org
Phone: +91 93217 27752
We acknowledge reports within 24 hours and aim to resolve them within 15 days.