How does PropExecutor keep each firm's data separate?
Quick answer
Every firm's records carry its organization ID, and the database enforces row-level security: each request runs with the signed-in firm's context, and the database itself refuses rows from any other firm. Isolation does not depend on application code remembering to filter. Operator access uses a separate, dedicated database role.
Detailed answer
PropExecutor is multi-tenant: many firms share one platform. The design goal is that one firm can never see another's data, even if code has a bug.
How isolation works
- Organization ID on every tenant table: accounts, traders, trades, rule sets, credits and more.
- Row-level security policies: the database filters every query by the current firm.
- Request context: each request sets the firm from the verified session token, never from anything the browser sends.
Why at the database level
Application-level filtering relies on every query being written correctly. Database-level policies apply even to a query that forgot to filter, so a mistake fails safe.
Operator access
PropExecutor's own operators reach cross-firm data only through a separate database role reserved for that purpose, not through the connection firms' sessions use.
Exceptions, stated
A few platform-level tables, such as the public price list and purchases made before a firm exists, have no firm ID by design. They are not readable through firms' sessions.
Traders
A trader's terminal session is scoped to one account, taken from the session token, so a trader cannot address any other account even within the same firm.
PropExecutor team · Updated
Related questions
All 11 questions in Security, data and reliability · Every category