Security & Controls

An investment operating system that can execute needs a higher control standard.

As Hedgtrade connects research and portfolio intelligence to authorized broker accounts, authentication, permissions, order controls, auditability, reconciliation and operational resilience become core product requirements rather than back-office details.

AccessHedgtrade secure connectivity
RiskHedgtrade risk controls
PortfolioHedgtrade portfolio controls
AuditHedgtrade reporting and audit
Control principles

Authorize narrowly. Record everything. Reconcile continuously.

Permissioned access

Connected accounts should use delegated authorization and scoped permissions rather than sharing broker passwords with Hedgtrade.

Role separation

Read-only portfolio access, strategy control and execution authority can be separated according to deployment requirements.

Audit history

Targets, approvals, orders, broker acknowledgements, fills, cancellations and errors should remain reconstructable.

Duplicate protection

Idempotent order handling is designed to reduce accidental duplicate execution after retries, crashes or reconnects.

Broker reconciliation

Actual broker positions remain the execution source of truth and are reconciled against Hedgtrade's internal state.

Risk controls

Account, strategy, instrument and portfolio limits can be applied before execution where the deployment supports them.

Custody boundary

Connected trading does not mean Hedgtrade becomes the custodian.

Client assets remain at the underlying broker or custodian. Hedgtrade may, where specifically enabled and authorized, retrieve account information and transmit or manage trading instructions through supported broker connectivity. Scope, permissions and legal responsibilities depend on the relevant deployment and agreements.

Important distinction.

Hedgtrade can provide an order and execution management layer without taking possession of client cash or securities.

Broker AssetsBroker-held portfolio
Hedgtrade Control LayerHedgtrade control layer
Enterprise review

Validate the deployment, not a generic checklist.

Requirements such as SSO/SAML, role design, encryption, retention, disaster recovery, audit exports, deployment architecture, API permissions and compliance controls should be validated against the actual client scope.

  • User and role model
  • Broker authorization and token handling
  • Order and risk permissions
  • Audit / retention requirements
  • Business continuity and recovery
  • Integration and security evidence
IntegrationHedgtrade integration
PortfolioHedgtrade portfolio
ReportingHedgtrade reporting
RiskHedgtrade risk