Account Safety
Account access should protect the research record without overstating security.
Stock Analysis Desk keeps account language focused on user privacy, verified safeguards, and documented limitations.
Quick read
Stock Analysis Desk keeps account language focused on user privacy, verified safeguards, and documented limitations.
Watch for
Stale data. Missing contradiction. Weak sources.
Try it
View contact optionsAccount safety
Verified protections and current limitations.
This page describes protections observed in the implementation. It does not claim complete security or regulatory approval.
Verified in the current implementation
- Passwords are hashed by the API before storage.
- Login and registration endpoints use server-side rate limiting.
- Access tokens include an expiration time.
- Private workspace routes verify the account token before showing protected screens.
Limitations to document or harden
- Browser account sessions use an HttpOnly API cookie. Legacy Bearer-token support remains for older clients and WebSocket compatibility.
- Email verification, password reset, data-retention windows, backup handling, and account-deletion operations are not publicly documented yet.
Operator and Contact
Public contact details should be explicit, not guessed.
When the owner provides official contact and operator details, this page will show them from central configuration. Until then, missing fields are labeled plainly.
- Legal operator or company name
- This information has not yet been publicly documented.
- Founder or responsible operator
- This information has not yet been publicly documented.
- Operating jurisdiction
- This information has not yet been publicly documented.
- General support email
- This information has not yet been publicly documented.
- Account-deletion contact
- This information has not yet been publicly documented.
- Security-reporting contact
- This information has not yet been publicly documented.
- Expected beta support-response window
- This information has not yet been publicly documented.
- Market-data provider disclosure
- This information has not yet been publicly documented.
Owner config: NEXT_PUBLIC_OPERATOR_LEGAL_NAME
Owner config: NEXT_PUBLIC_RESPONSIBLE_OPERATOR
Owner config: NEXT_PUBLIC_OPERATOR_JURISDICTION
Owner config: NEXT_PUBLIC_SUPPORT_EMAIL
Owner config: NEXT_PUBLIC_ACCOUNT_DELETION_EMAIL
Owner config: NEXT_PUBLIC_SECURITY_EMAIL
Owner config: NEXT_PUBLIC_BETA_SUPPORT_WINDOW
Owner config: NEXT_PUBLIC_MARKET_DATA_DISCLOSURE
What users should avoid sending
Do not send brokerage credentials, government identifiers, payment-card data, full brokerage statements, private keys, or other unnecessary sensitive information through support requests or research notes.
What the account protects
Your watchlists, notes, and paper-research history are private to your account. Stock Analysis Desk does not need brokerage credentials for the current public beta workflow and does not place trades for you.
Continue the process
