Security
Security and control, designed into the platform.
Trading and education platforms hold sensitive data and act on real accounts. AlphaSync’s security architecture is designed around limiting access, controlling every order and keeping a record of what happened.
Our posture
We describe design intent — and certify nothing we haven’t earned.
This page explains how the platform is designed. It does not claim certifications, audits or regulatory approvals: none are listed here until they are completed and can be evidenced.
Security domains
How the architecture is designed
Secure architecture
Layered separation of interfaces, services, data and broker connectivity, with the risk engine inside the order path.
Authentication
Account sign-in with email or Google; broker connections authenticated directly with the broker via official APIs — AlphaSync does not store broker passwords.
Authorisation & RBAC
Role-based permissions, seat management and admin controls per organisation, designed around least privilege.
API security
Scoped API keys that grant only the permissions requested, rate limits per key, and an isolated sandbox for development.
Data protection
Personal data handled under the IT Act, 2000 and the Digital Personal Data Protection Act, 2023, as set out in our Privacy Policy.
Auditability
Automated orders tagged to their source strategy; orders, modifications and risk events recorded for review and export.
Trading controls
Mandatory risk fields on strategies, pre-trade limit checks, automatic square-off and kill-switches.
Monitoring
Risk events recorded alongside orders; a public status page with live reachability checks.
Issue reporting
In-product reporting lets users flag problems with screenshots and track each report’s status.
Regulatory position
Clear about what AlphaSync is — and is not.
AlphaSync is a technology platform operated by Vianmax Techno Ventures Private Limited. It is not a stock broker, investment adviser or research analyst and is not registered with SEBI in any such capacity.
- Orders route through registered brokers under SEBI’s retail algo framework
- Automated orders carry source tagging for audit
- Educational use runs on 30-day delayed market data (effective 1 July 2026)
- AI output is informational and educational, not advice
- Risk Disclosure published and linked from every page
Responsible disclosure
Report a vulnerability.
If you believe you have found a security issue in AlphaSync, please write to alphasync@vianmax.com with “Security report” in the subject. Please do not access data that isn’t yours or disrupt the service while testing.
Security review for your procurement team
Institutions and partners can request an architecture and security walkthrough with the AlphaSync team.