TraderClub.ai
Security by architecture

Zero-custody: your credentials never leave your machine

The Expert Advisor runs inside YOUR MetaTrader 5, on your computer or VPS. Your money stays at your broker, your password stays with you — and every event lands on the audit ledger.

Where your credentials live

The structural difference between TraderClub.ai and the typical server-side copy model isn't a promise — it's the path an order travels.

TraderClub.ai (zero-custody)

You

broker password stays here

EA in your MT5

on your machine or VPS

Your broker

your money stays here

The platform sends only the signal (HMAC-signed). Login and capital never touch our servers.

Typical server-side model

You

hand over login and password

Their server

credentials on third-party infra

Broker

accessed on your behalf

In that model, a breach of the service's server exposes access to your broker account.

Security by architecture

The four layers

Every layer is verifiable in the product — none of it relies on blind trust.

HMAC-signed orders

Every instruction that reaches the EA carries an HMAC signature with a timestamp and a unique identifier. The EA drops any message that fails validation — a forged or tampered order simply never executes.

Credentials encrypted at rest

Whatever you configure locally is encrypted at rest. We don't have — and don't want — access to your broker password in the platform's default model.

Hash-chain audit ledger

Signals and execution events are chained by hash, each one pointing to the previous. Altering a past record would break the whole chain — which is why the track record is public and verifiable, losses included.

Risk limits and kill-switch

You set max daily loss, lot size and risk per trade. The kill-switch pauses all execution instantly, and the EA enforces those limits locally, on your machine.

What we NEVER ask for

If anyone asks in our name, it's a scam. Report it to support.

Your broker password to run on our servers — server-side execution only exists if YOU explicitly opt into it

Money transfers to our account — your capital stays at your broker, always

Withdrawal rights or any power to move your funds

2FA codes, seed phrases or private keys of any wallet

What stays with you: password, money, the decision to trade and the off switch

Trading involves real risk of loss. Zero-custody protects access to your account — it does not remove market risk. Only trade capital you can afford to lose.

Security questions

Do you have access to my broker account?

No. The EA runs inside your MetaTrader 5, on your machine or VPS, and it is the EA that talks to the broker. The platform only sends HMAC-signed signals — login and password never reach our servers in the default model.

What happens if your servers get breached?

An attacker would find no broker credentials, because they aren't there. And they couldn't inject fake orders: without the correct HMAC key, your EA discards the message.

How do I know the track record wasn't edited?

Every signal enters the hash-chain ledger before the outcome, with entry, stop and targets. Since each record references the previous hash, editing the past would break the chain — and the full history, losses included, is open for audit.

Can I stop everything immediately?

Yes. The kill-switch pauses all execution instantly, and you can also simply turn off the EA in your MT5 — the final control is physical and sits on your side.

Does zero-custody mean there is no risk?

No. Zero-custody removes custody risk (nobody but you touches your capital and credentials), but market risk still exists. Past performance does not guarantee future results.

Prêt à opérer avec l'IA à vos côtés ?

Rejoignez la communauté, connectez votre courtier et laissez l'IA travailler avec vous.