Home Features Battle Mode How It Works Pricing Leaderboard Get Started
Trust • Security Audits

Security & Compliance

Explore our platform's security certifications, independent code penetration tests, audit logs, and institutional-grade safety measures.

5 min read Last updated: June 2026

1 Security Architecture

BacktestX employs an advanced, defense-in-depth security architecture designed to isolate trading algorithms, protect private API credentials, and safeguard proprietary code databases.

Client-Side Protection

  • Encrypted Key Storage User API credentials and brokers tokens are fully client-side encrypted before transfer.
  • Hardware MFA Support for biometric and security-key multi-factor authentication (WebAuthn).

Server-Side Protection

  • Isolated Execution Sandboxes Each algorithm simulation is executed in a dedicated, ephemeral virtual container.
  • Continuous Audits Log Strict, read-only system log trailing showing all system file modifications.

2 Independent Penetration Tests

We believe in verifiable security. BacktestX contracts independent, CREST-accredited cybersecurity firms to perform regular white-box and black-box penetration tests on our web application and API boundaries.

Latest Penetration Test: Passed (May 2026)

An external audit conducted by SecOps Laboratories detected zero critical or high-risk vulnerabilities. All minor recommendations were successfully patched and validated in our build pipelines.

Our testing covers application-level vulnerabilities, container isolation configurations, distributed denial of service (DDoS) resilience, and API credential leakage prevention.

3 SOC 2 & ISO Compliance

Our operations, infrastructure management, and product lifecycles follow standard control guidelines to ensure your trading strategies remain fully confidential and high-performing.

SOC 2 Type II

System audits evaluating security, confidentiality, and processing integrity controls over continuous 6-month windows.

ISO/IEC 27001

Adherence to global standard guidelines for establishing, operating, and auditing our Information Security Management System (ISMS).

GDPR compliant

Strict European guidelines governing the export, processing, and absolute deletion of personal data on-demand.

4 Data Encryption

All data managed by BacktestX is classified and encrypted according to its sensitivity levels using standard cryptographic protocols.

AES-256 and TLS 1.3 Encryption standards

All databases storing customer records, strategy files, and order details are encrypted at rest with AES-256. Data moving over public networks utilizes TLS 1.3 transport security protocols.

5 Infrastructure Security

We deploy our cloud infrastructure on Tier-IV cloud providers (AWS and Google Cloud Platform) offering superior physical safety and networking guards.

DDoS Protection

Cloudflare Magic Transit shields our API network from massive Layer 3, 4, and 7 DDoS attacks, providing continuous performance even during global high-volatility events.

CI/CD Pipeline Security

All code updates undergo automated static analysis (SAST) and software composition analysis (SCA) to detect third-party library vulnerabilities before production deployment.

6 Vulnerability Disclosure Policy

We welcome security researchers and developers to audit our platform. If you discover a vulnerability, please report it immediately through our coordinated disclosure program.

Send an encrypted email to security@backtestx.in containing reproducing steps. We commit to acknowledging reports within 24 hours and providing status updates throughout the patching process. Ethical hacking reports are eligible for our bug bounty programs.