Account
Security
The short version: no passwords, no broker credentials, and a device list you control.
Signing In
Ledgerr has no password to steal. You enter your email, we send a six-digit code to it, and that code signs you in. Codes are short-lived and single-use, and repeated requests are rate limited.
Your inbox is the key
Anyone who can read your email can sign in as you. Protect that account with two-factor authentication — it is the single highest-value thing you can do for your Ledgerr security.
Devices and Sessions
- Account Settings lists every device holding a session, with where and when it signed in.
- Ending a session logs that device out immediately.
- Signing in on a new device does not end the others, so you can run desktop and phone together.
What We Never Ask For
- Your broker password. MetaTrader syncs through a key you issue; cTrader authorises through its own OAuth screen.
- Withdrawal permissions of any kind. Nothing in Ledgerr can move money out of a trading account.
- Card numbers. Payments happen on PayPal’s or Binance’s own checkout.
What Ledgerr Can Do on Your Accounts
Reading trade history and account balances, always. Placing orders, only on accounts you have made followers in a Trade Engine link, and only to mirror the source you chose. Revoking access in cTrader, disconnecting the account, or deleting the EA key each stop it at once.
Reporting Something
Found a vulnerability, or seen activity you do not recognise? Tell us before telling anyone else, through the contact page. Include what you did, what happened and when.