Security

Last updated: 23 May 2026

Your trade history and tax data are among the most sensitive financial records you hold. This page explains the technical and organisational controls TradeLog NZ uses to protect them.

TLS 1.3 · AES-256

Encryption

SOC 2 Type II

Infrastructure

PCI DSS Level 1

Payments

Privacy Act 2020

NZ Privacy

Encryption

All data in transit between your browser and TradeLog NZ is encrypted using TLS 1.3. Connections that attempt to use older, weaker protocols are rejected.

Data at rest — including your trade records, tax calculations, and personal information stored in our database — is encrypted using AES-256, provided by both Railway (our hosting platform) and Supabase (our database provider).

Infrastructure — Railway (SOC 2 Type II)

TradeLog NZ is hosted on Railway, which holds a SOC 2 Type IIcertification. This means an independent auditor has examined and verified Railway's security controls — not just that the controls exist (Type I), but that they operated effectively over a sustained period (Type II).

Railway runs on Google Cloud Platform. You can review Railway's full trust centre, including their SOC 3 report (publicly available), at trust.railway.com.

Railway's documented controls include: encryption at rest and in transit, access control and logging, data backup and erasure capabilities, separate production environments, network firewalls, endpoint detection and response, and employee security training.

Authentication — Supabase

User authentication is handled by Supabase, an enterprise-grade backend platform. Authentication uses industry-standard JWT-based sessions. Passwords are hashed using bcrypt and are never stored in plain text. Sessions are validated server-side on every protected request — we do not rely solely on client-side cookies.

Access to your account data is restricted strictly to your authenticated session. No TradeLog NZ staff can view your trade data or tax calculations without explicit support access, which is logged.

Payments — Stripe (PCI DSS Level 1)

All subscription payments are processed by Stripe, a PCI DSS Level 1 certified payment processor — the highest level of payment security certification available. PCI DSS Level 1 requires an annual audit by a Qualified Security Assessor and quarterly network scans.

TradeLog NZ never sees, handles, or stores your card number, CVV, or full card details. These are entered directly into Stripe's secure hosted fields and transmitted to Stripe's servers. We only store a Stripe customer ID and your subscription status.

NZ Privacy Act 2020

TradeLog NZ complies with the Privacy Act 2020 (New Zealand). Under this Act, you have the right to:

  • Access the personal information we hold about you
  • Correct any inaccuracies in that information
  • Request deletion of your account and associated data
  • Know how your information is used and who it is shared with

We collect only the minimum information necessary to provide the service. We do not sell, rent, or share your personal information with third parties for marketing purposes. Full details are in our Privacy Policy.

What data we hold

  • Account information — name, email address, account preferences
  • Trade records— instrument, open/close dates, P&L in original currency and NZD, broker name
  • Expense records — amount, category, description, date
  • Tax calculations — computed summaries derived from your trade and expense data
  • Billing information — Stripe customer ID and subscription status only (no card data)

We do not collect or store broker credentials, trading account passwords, or live market data beyond what you explicitly import.

Data retention and deletion

Your data is retained for as long as your account is active. If you close your account, your trade records, tax calculations, and personal information are permanently deleted within 30 days. Anonymised, aggregated usage analytics (which cannot identify you) may be retained for product improvement.

To request account deletion, email [email protected] or use the account settings page.

Security headers

TradeLog NZ serves the following security headers on all responses:

  • Content-Security-Policy — restricts which origins can load scripts, styles, and frames
  • Strict-Transport-Security — enforces HTTPS for all connections for 12 months
  • X-Frame-Options: DENY — prevents the site being embedded in iframes (clickjacking protection)
  • X-Content-Type-Options: nosniff — prevents MIME-type sniffing attacks
  • Permissions-Policy — restricts access to camera, microphone, and geolocation APIs
  • Cross-Origin-Opener-Policy — isolates the browsing context to mitigate Spectre-class attacks

Responsible disclosure

If you discover a security vulnerability in TradeLog NZ, please report it responsibly by emailing [email protected]. Include a description of the vulnerability and steps to reproduce it. We will acknowledge your report within 48 hours and aim to resolve confirmed vulnerabilities promptly.

Please do not publicly disclose a vulnerability until we have had a reasonable opportunity to investigate and remediate it. We do not currently operate a formal bug bounty programme but we appreciate responsible disclosures.

Questions

For security-related questions or to report an issue, contact [email protected]. For privacy-related questions, see our Privacy Policy or email [email protected].