Security

What follows describes how the product is built, not what we aspire to. Each point is a property of the code.

There is no password to steal

Signing in sends a six-digit code to your email. The code is the credential. There is no password field in the product, no password stored anywhere, and no password reset flow — because there is nothing to reset. A breach of our database yields no password to try against your other accounts.

A database read cannot sign anyone in

Your session is a random token held in your browser. What we store is a SHA-256 hash of it, never the token itself. Someone reading the database — a backup, a log, a copied replica — gets hashes, and a hash cannot be presented as a session.

Sessions expire after 30 days of inactivity and cannot outlive 180 days regardless of use. You can see every active session and end any of them, including all of them at once.

The session cookie cannot be scoped loosely

The cookie uses the __Host- prefix, which browsers enforce: it cannot carry a domain attribute and cannot be scoped to anything but the exact host that set it. It is httpOnly, so no script on the page can read it, and requests that change something are checked against an allowlist of origins before they reach any code.

Staff are a separate system, not a flag

Internal staff who can see customer records sign in through a different table, with a different session cookie and a different guard. A customer session cannot be used as a staff session and a staff session cannot be used as a customer one — not by policy, but because they are different types backed by different tables. There is no staff sign-up: an internal account is created deliberately, by hand.

What we transmit, and what we never do

Compoyo never executes trades. There is no connection to your funds, no order placement and no portfolio management anywhere in the product. A signal is information; you act on it in your own brokerage account.

When you ask for professional support, a lead is sent to a support desk — and only after your email and phone are verified and your consent is recorded with a timestamp. Your demo profit and loss and your broker are never part of what is sent.

Found something wrong? Tell us. A report that turns out to be right is worth more to us than a page that looks reassuring.