| Orders | What your integration sent and what the provider answered. The provider’s raw payload is removed from every row we serve, so you read back the documented shape and nothing more |
| Executions and positions | What the connected provider reports. A money field the provider hasn’t reported is null, never an invented 0 |
| Connect registrations | The account number, the login name at the provider and the trader’s email. Never a password: the trader enters their own credential, so the firm’s data and the trader’s secret never meet |
| Keys | A SHA-256 hash of each Trading API and Partner key, never the key itself, so a read of our database can’t produce a working key. A Venue key is hashed and also kept encrypted, so that retrying its creation returns the same key |