> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trdrs.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Data policy

> Answer your security review: what trdrs stores, who can see it, and what it never does with it.

These are plain answers to the questions every security review asks: what we store, who can see
it, and what we never do with it. Share this page with whoever reviews your integration.

## Market data belongs to the trader

When a trader connects their own account at a provider, their market data flows under their own
entitlement. That's a rule of the platform, not a detail of one provider:

* A trader's entitled data serves that trader alone.
* Caches of it are scoped to the trader's session.
* We never pass one trader's feed on to other users.
* No firm route sends a trader's entitled data to the firm or to anyone else.

Shared data reaches traders only through a feed that the provider or the firm licenses for sharing.
If we don't hold the license, the route doesn't exist. We never serve delayed data as a quiet
fallback.

## What trdrs stores

| We store | What it holds |
| - | - |
| Orders | What your integration sent and what the provider answered. The provider's raw payload is removed from every row we serve, so you read back the documented shape and nothing more |
| Executions and positions | What the connected provider reports. A money field the provider hasn't reported is `null`, never an invented `0` |
| Connect registrations | The account number, the login name at the provider and the trader's email. Never a password: the trader enters their own credential, so the firm's data and the trader's secret never meet |
| Keys | A SHA-256 hash of each Trading API and Partner key, never the key itself, so a read of our database can't produce a working key. A Venue key is hashed and also kept encrypted, so that retrying its creation returns the same key |

## What a firm can see

A firm sees the accounts it issued or pre-registered: their registration status, usage and audit
events. It can't see a trader's credential, a trader's entitled market data, or anything that
belongs to another firm. The Trading API, Partner and Venue key scopes are separate at the routing
layer, so this is enforced before any handler runs.

## What we ask of you

The [integration self-check](/providers/requirements) asks for the same care in return: keys stay on
your server, and trader credentials never appear in your logs or ours. Nothing is sent to us; the
self-check runs in the sandbox and you read its result there.

If you find personal data in a response that this page doesn't explain, tell your trdrs contact and
we'll treat it as a defect.
