PropExecutorFor evaluators · 11 questions

Security, data and reliability

How PropExecutor separates firms' data, secures trader and admin sessions, handles personal data and stays consistent under load.

  1. How does PropExecutor keep each firm's data separate?

    Every firm's records carry its organization ID, and the database enforces row-level security: each request runs with the signed-in firm's context, and the database itself refuses rows from any other firm. Isolation does not depend on application code remembering to filter. Operator access uses a separate, dedicated database role.

  2. Can one firm see another firm's data?

    No. Firms are separated by database row-level security tied to each signed-in firm, and every API key and panel session is bound to one organization. Server names, account numbers and passwords never resolve across firms, and analytics are pinned to the requesting firm whatever the request asks for.

  3. How are trader sessions secured?

    Trader sessions are scoped to exactly one trading account, which is taken from the signed session token and never from the request. Access tokens last up to 15 minutes and are renewed with a refresh token that rotates on use. Rotating the password, reassigning or archiving the account revokes every session for it.

  4. How long can a revoked session keep working?

    Up to 15 minutes. Revoking a session (by rotating the password, reassigning or archiving the account) cancels its refresh token immediately, but the short-lived access token already in an open terminal stays valid until it expires, which is at most 15 minutes. New logins with the old password fail at once.

  5. How are admin sign-ins protected?

    Admin panel sign-in uses a one-time code sent to the user's email, or Sign In With Google, with no passwords to steal or reuse. Sessions use short-lived access tokens and refresh tokens that rotate on every use, so a stolen refresh token that is replayed is rejected. API keys are separate, scoped and revocable.

  6. Is trader data shared with third parties?

    PropExecutor stores only a trader's name and email and their trading activity, and does not sell or market to your traders. Traders have no relationship with PropExecutor. Data is processed by the infrastructure providers needed to run the platform, such as cloud hosting and email delivery, as described in the privacy policy.

  7. What data does PropExecutor store about traders?

    For each trader, PropExecutor stores the name and email on the trader record, and for each trading account its balance, positions, trades, orders, rule flags and status history. It does not store identity documents, payment details, addresses or phone numbers, which stay with your own KYC and payment providers.

  8. Does PropExecutor store card details?

    No. PropExecutor never sees card details. Your firm's purchases from PropExecutor are paid through a Dodo Payments checkout, where card details are entered with Dodo, the merchant of record. Your traders' payments go through your own provider and never touch PropExecutor at all.

  9. What happens if a PropExecutor server goes down?

    The backend is designed to run as more than one instance behind a load balancer, with a reconciler keeping each instance's view of positions, orders and balances consistent with the database every 10 seconds. Write paths are safe across instances, and the service shuts down gracefully, finishing in-flight requests before stopping.

  10. How does PropExecutor handle orders that arrive at the same time?

    Each order takes a per-account lock and is checked and written inside one database transaction, with open positions read from the database in that transaction. Simultaneous orders on the same account are therefore processed one after another, and limits such as maximum positions hold, even across server instances.

  11. Does PropExecutor have a platform-wide kill switch?

    Yes. PropExecutor's operators have a platform-wide trading halt for emergencies, such as a price feed problem that would produce wrong fills. It stops new trading across the platform until the issue is resolved. It is an operator control, not something firms or traders can trigger.