How does PropExecutor keep each firm's data separate?

Quick answer

Every firm's records carry its organization ID, and the database enforces row-level security: each request runs with the signed-in firm's context, and the database itself refuses rows from any other firm. Isolation does not depend on application code remembering to filter. Operator access uses a separate, dedicated database role.

Detailed answer

PropExecutor is multi-tenant: many firms share one platform. The design goal is that one firm can never see another's data, even if code has a bug.

How isolation works

  • Organization ID on every tenant table: accounts, traders, trades, rule sets, credits and more.
  • Row-level security policies: the database filters every query by the current firm.
  • Request context: each request sets the firm from the verified session token, never from anything the browser sends.

Why at the database level

Application-level filtering relies on every query being written correctly. Database-level policies apply even to a query that forgot to filter, so a mistake fails safe.

Operator access

PropExecutor's own operators reach cross-firm data only through a separate database role reserved for that purpose, not through the connection firms' sessions use.

Exceptions, stated

A few platform-level tables, such as the public price list and purchases made before a firm exists, have no firm ID by design. They are not readable through firms' sessions.

Traders

A trader's terminal session is scoped to one account, taken from the session token, so a trader cannot address any other account even within the same firm.

PropExecutor team · Updated

All 11 questions in Security, data and reliability · Every category