Security & Compliance
Explore our platform's security certifications, independent code penetration tests, audit logs, and institutional-grade safety measures.
Contents
1. Security Architecture 2. Independent Audits 3. SOC 2 Compliance 4. Data Encryption 5. Infrastructure Security 6. Vulnerability Disclosures1 Security Architecture
BacktestX employs an advanced, defense-in-depth security architecture designed to isolate trading algorithms, protect private API credentials, and safeguard proprietary code databases.
Client-Side Protection
-
Encrypted Key Storage User API credentials and brokers tokens are fully client-side encrypted before transfer.
-
Hardware MFA Support for biometric and security-key multi-factor authentication (WebAuthn).
Server-Side Protection
-
Isolated Execution Sandboxes Each algorithm simulation is executed in a dedicated, ephemeral virtual container.
-
Continuous Audits Log Strict, read-only system log trailing showing all system file modifications.
2 Independent Penetration Tests
We believe in verifiable security. BacktestX contracts independent, CREST-accredited cybersecurity firms to perform regular white-box and black-box penetration tests on our web application and API boundaries.
An external audit conducted by SecOps Laboratories detected zero critical or high-risk vulnerabilities. All minor recommendations were successfully patched and validated in our build pipelines.
Our testing covers application-level vulnerabilities, container isolation configurations, distributed denial of service (DDoS) resilience, and API credential leakage prevention.
3 SOC 2 & ISO Compliance
Our operations, infrastructure management, and product lifecycles follow standard control guidelines to ensure your trading strategies remain fully confidential and high-performing.
SOC 2 Type II
System audits evaluating security, confidentiality, and processing integrity controls over continuous 6-month windows.
ISO/IEC 27001
Adherence to global standard guidelines for establishing, operating, and auditing our Information Security Management System (ISMS).
GDPR compliant
Strict European guidelines governing the export, processing, and absolute deletion of personal data on-demand.
4 Data Encryption
All data managed by BacktestX is classified and encrypted according to its sensitivity levels using standard cryptographic protocols.
All databases storing customer records, strategy files, and order details are encrypted at rest with AES-256. Data moving over public networks utilizes TLS 1.3 transport security protocols.
5 Infrastructure Security
We deploy our cloud infrastructure on Tier-IV cloud providers (AWS and Google Cloud Platform) offering superior physical safety and networking guards.
DDoS Protection
Cloudflare Magic Transit shields our API network from massive Layer 3, 4, and 7 DDoS attacks, providing continuous performance even during global high-volatility events.
CI/CD Pipeline Security
All code updates undergo automated static analysis (SAST) and software composition analysis (SCA) to detect third-party library vulnerabilities before production deployment.
6 Vulnerability Disclosure Policy
We welcome security researchers and developers to audit our platform. If you discover a vulnerability, please report it immediately through our coordinated disclosure program.
Send an encrypted email to security@backtestx.in containing reproducing steps. We commit to acknowledging reports within 24 hours and providing status updates throughout the patching process. Ethical hacking reports are eligible for our bug bounty programs.