← ← Back to Home
DSGVO · END-TO-END · TRANSPARENT

Privacy & Security

Your trading and tax data is among the most sensitive information you entrust to us. We treat it the way we would expect ourselves: hosting exclusively in Germany, end-to-end encryption, no tracking, and full control for you. This page explains in plain language how we do it technically.

🔒 TLS 🇪🇺 EU-Hosting ⚖️ DSGVO 🔐 2FA
§ 01

🌍 Where your data lives & 🔒 Encryption at every layer

🇪🇺

🌍 Where your data lives

All data is stored and processed exclusively on servers in Germany — at HostEurope GmbH in Cologne, one of the most established German hosting providers, which we have trusted as a customer since 2001. A data processing agreement pursuant to Art. 28 GDPR is in place with the host. Your data does not leave the EU.

More about the host: www.hosteurope.de
🔐

🔒 Encryption at every layer

The connection to sTraderZ.com runs exclusively over TLS/HTTPS — unencrypted requests are automatically redirected to HTTPS. Your broker credentials and API tokens are additionally stored encrypted with AES-256-GCM. This encryption is so strong that not even our administrators can read your stored credentials in plain text.

§ 02

🚫 No tracking, no third-party fonts

We use no Google Analytics, no Facebook pixel, and no advertising or tracking networks. We host all fonts ourselves on our servers in Germany — when a page loads, your IP address is not transmitted to any external font service. Only technically necessary cookies are used (login, language setting, dark mode), which is why no cookie banner is required.

§ 03

🛡️ Security architecture

Protection applies at every layer — from login through data import to the API. The key mechanisms:

🔐 01 / 09
TFA
🔐 Two-factor authentication
TOTP via any authenticator app, 10 one-time backup codes for emergencies, and push confirmation directly in the sTraderZ app.
🛡️ 02 / 09
LOGIN
⏱️ Brute-force protection
After several failed attempts, login is temporarily locked per IP address. Automated password guessing runs into a dead end.
🎫 03 / 09
CSRF
🛡️ CSRF protection
Every state-changing action is secured by a session-bound security token — forged requests from foreign sites are rejected.
📄 04 / 09
XXE
📄 Hardened data import
When importing your broker exports (e.g. IBKR FlexQuery), loading of external XML entities is disabled — the well-known XXE attack vector is closed.
📦 05 / 09
UPLOAD
⬆️ Upload hardening
File uploads are restricted to permitted formats and checked for type and size before being processed.
🔑 06 / 09
IDOR
👤 Strict access separation
Before every data access, the system verifies ownership. You see only your own trades, accounts, and analyses — never those of other users.
🪙 07 / 09
JWT
🔑 Signed app sessions
The mobile app and the API authenticate via cryptographically signed tokens (JWT/HS256), whose authenticity is verified on every request.
🔒 08 / 09
TLS
🔒 Enforced HTTPS
All traffic is transport-encrypted. HTTP requests are consistently redirected to HTTPS.
🧱 09 / 09
HEADERS
🧱 Hardening security headers
Every server response carries modern protective headers: clickjacking protection (X-Frame-Options), protection against MIME-type tricks (X-Content-Type-Options), browser-side HTTPS enforcement (HSTS), data-minimal referrer handling, and project-wide disabling of sensitive browser APIs (camera, microphone, location).
§ 04

👤 You stay in control & 🔗 Who gets what — broken down honestly

👤 You stay in control

You decide what is visible and what happens with your data:

  • Enable two-factor authentication yourself at any time
  • Privacy mode: hide balances and amounts on demand
  • Granular profile visibility — you decide what is public
  • Export your trades as CSV or Excel at any time

🔗 Who gets what — broken down honestly

We name every service explicitly instead of making blanket promises:

§ 05

📄 Your rights under the GDPR

⚖️ 📄 Your rights under the GDPR

You always have the right to access, rectification, erasure, restriction of processing, data portability, and objection. We will delete your account and associated data at any time upon request — only documents subject to statutory retention (e.g. invoices) are kept for the prescribed period. A short email to us is enough for any request.

❓ ✅ Continuous quality and security review

After every update, automated tests verify that the platform works without errors. In addition, code changes undergo an AI-assisted security and code review before every release. This way, improvements ship quickly without compromising stability.

Matthias Sax — Gründer von sTraderZ.com

👋 Who is behind sTraderZ.com

Owner-operated · Matthias Sax GmbH · Fürth, Germany
⌨️ 30+ years of code & entrepreneurship 🏛️ Foundation founder 🎓 Graduate in business information systems 📜 PMP · Scrum Master · Product Owner 🏢 Projects for Siemens, Mercedes-Benz, Infineon & co.

sTraderZ.com is not an anonymous startup or a venture-capital project. The platform is run by the owner-operated Matthias Sax GmbH, based in Fürth, Germany — with a clear imprint, a reachable contact, and a founder who trades himself.

→ More about Matthias and how sTraderZ.com came to be

📖 More details

You can find the full legal information in our Privacy Policy and in the Imprint.

Questions about data protection? Just email us at: ✉️ margincall@straderz.com