Security

Security and broker integration safeguards

A public overview of how Optioneer protects broker-synchronized data, keeps integrations read-only, and gives users control over connection and deletion choices.

Broker Sync is read-only and used only for portfolio tracking and transaction import.

Optioneer does not place trades, execute orders, rebalance accounts, or request trading permissions.

Read-only broker access for synchronization and analytics.

No trading permissions, automated trading, or brokerage account control.

User-controlled disconnection, revocation, and deletion workflows.

Overview

Optioneer is built as a portfolio tracking and analytics product for options traders. The platform helps users understand positions, balances, transaction history, and options activity they choose to synchronize or import.

Optioneer does not place trades, automate trading, manage brokerage accounts, or execute orders on behalf of users.

Read-only broker integrations

Broker connectivity is provided through SnapTrade and designed for read-only access. Optioneer uses broker data for portfolio synchronization, analytics, and user-visible account summaries. We do not request permissions intended for order placement or trading authorization.

Optioneer cannot place trades

Users remain fully responsible for their brokerage accounts. Optioneer cannot submit, modify, cancel, or route orders, and the product does not include order workflows. Optioneer does not place trades or execute orders on behalf of users. Any brokerage activity remains inside the user's broker account and broker platform.

Encryption and secure transport

Optioneer uses HTTPS/TLS for secure transport between browsers, backend services, and authorized service providers. Sensitive records are protected using managed database and infrastructure controls, with access limited to authenticated application flows and operationally required personnel.

Data storage practices

Broker-synchronized data is stored so Optioneer can show positions, balances, transactions, options activity, and portfolio analytics to the account owner. We avoid storing data that is not needed for the product experience, and we separate user authorization from public product content.

Broker token/access handling

Broker access is handled through user-authorized connection flows. Access credentials or tokens, where applicable, are treated as sensitive secrets, scoped to synchronization needs, and never displayed in the product interface. Disconnecting in Optioneer stops local synchronization. Because it does not currently delete the provider-side authorization, users should also revoke access directly with their broker where that control is available.

Immutable broker event architecture

At a high level, Optioneer records broker sync activity as durable portfolio events and then derives the portfolio views users see in the application. This event-oriented approach helps preserve an auditable history of imported broker changes without exposing internal systems or operational implementation details.

Account disconnection and revocation

Broker connectivity and authorization are provided through SnapTrade's secure connection portal. Users can disconnect Broker Sync from Optioneer to stop future local synchronization. The current Optioneer disconnect action preserves portfolio history and does not delete the SnapTrade-side authorization. Where a broker offers a separate authorization dashboard, users should also revoke Optioneer access there to end broker-side authorization.

Data deletion process

Users can request deletion of imported broker data or deletion of their Optioneer account. Deletion requests are handled according to our privacy practices and legal retention obligations. See the Data Deletion page for the full public process.

Infrastructure/security best practices

  • Role-based access patterns for application data and administrative workflows.
  • Secure authentication and session handling for user accounts.
  • Production monitoring for availability, errors, and security-relevant anomalies.
  • Least-privilege handling for broker synchronization and support workflows.

Responsible disclosure/security contact

If you believe you have found a security issue, contact support@optioneer.io with a clear description, affected area, and safe reproduction steps. We ask that researchers avoid accessing, modifying, or disclosing data that does not belong to them.

Broker authorization methods

SnapTrade's connection portal uses the authorization method supported by each brokerage, which can vary by broker, account, and region. Optioneer applies the same read-only principle regardless of that method: synchronization and analytics, without trading permissions. The portal is the final source of truth for current availability.

Security contact

Questions about broker synchronization, data deletion, or responsible disclosure can be sent to the Optioneer team.

Contact Optioneer