TICKERALL!
Trust

Security reports

Last updated: September 24, 2026

We hold a live connection to your broker on your behalf, so a security problem here is not abstract. If you have found one, we want to hear about it — and this page says exactly what happens next, what we can offer, and what we cannot.

1. Reporting an issue

Email hello@tickerall.com with “Security” in the subject. A short description, the steps to reproduce it and what you think the impact is will get a faster answer than a scanner report. You do not need an account with us to report something, and you do not need to have a proof-of-concept exploit — a clear description of the flaw is enough.

2. What we do when we get one

  • We read it ourselves — there is no triage queue and no form to fill in.
  • We reply to tell you whether we could reproduce it, and what we intend to do.
  • We fix what is real. Our first report was fixed and live in production the same day.
  • We tell you when the fix ships, and we credit you here by name and handle if you want that. If a written reference describing what you found is useful to you, ask and we will write one.

3. We do not pay for reports

We do not run a bug bounty programme and we do not offer monetary rewards or goodwill payments. We are a very small, self-funded company; what we can offer is a real fix, a straight answer, public credit on this page, and a reference you can use. We would rather say that plainly here than have somebody spend their time expecting otherwise. Reports are welcome on those terms and we are grateful for them — the section below is not a formality.

4. In scope

  • tickerall.com — the website, the dashboard and the admin surfaces.
  • api.tickerall.com — the REST and WebSocket API.
  • mcp.tickerall.com — the MCP server and its OAuth endpoints.
  • Our published SDKs and the terminal app.
  • Authentication, session handling, API-key scoping, tier enforcement, and anything that lets one customer reach another customer's data. That last one is what we care about most.

5. Out of scope — please read this part

  • Broker servers. The MetaTrader servers we connect to belong to brokers, not to us, and they are not ours to offer for testing. Several of them drop a source IP that connects too often, which takes real customers offline — so do not test against them.
  • Anything that places, modifies or closes an order on an account that is not your own. That is somebody's money.
  • Another person's account or data, beyond the minimum needed to demonstrate that reaching it is possible. Tell us it is possible; do not collect what is behind it.
  • Denial of service, load testing and traffic floods, including against our API.
  • Social engineering of us, our customers, or our brokers; physical attacks; spam.
  • Third-party services we use (our payment processor, our authentication provider, our host) — report those to them, though we are glad to know about it.
  • Findings with no security consequence: missing headers with nothing behind them, version disclosure, self-XSS, best-practice scanner output with no demonstrated impact.

If you are unsure whether something is in scope, ask first. We will answer.

6. Good faith

If you stay inside the scope above, act in good faith, use only your own accounts and data, and give us a reasonable chance to fix the problem before telling anyone else, we will not pursue or support any action against you for the research. We cannot waive anyone else's rights — a broker's or a third party's — which is the reason the out-of-scope list above is specific.

7. Thank you

People who reported a real problem and gave us the chance to fix it first. Listed newest last, with whatever name and links they asked us to use.

  • MD Rabbi HossainLinkedInXAugust 2026

    Reported that our MCP OAuth server accepted client registrations with unvetted redirect URIs. Fixed the same day by enforcing a redirect-URI allowlist at registration.

Security · Ticker All!