Security
Avero is a software platform and is not a registered investment adviser or broker-dealer. Trading involves substantial risk of loss.
Account access
- Passwords are hashed with Argon2id. Sessions use JWT with short expiry.
- Multi-factor authentication is available for admin accounts. Enable in Account → Security.
- We never store trading credentials. Broker connections use trading-only API keys with withdrawals disabled.
API key handling
- Use trading-only keys with least privilege. Never provide withdrawal permissions.
- Keys are encrypted at rest and never logged.
- Rotate keys regularly and revoke unused keys.
Data protection
- Data in transit is TLS 1.2+.
- Personal data is used only for account operation and support.
- See Privacy Policy for details.
Risk controls
- Kill switch, daily loss limits, and per-trade risk limits are enforced server-side.
- Automation can lose money. You remain responsible for risk settings.
Risk Disclosure · Privacy · Terms