Security reporting
How to report a vulnerability or suspected account compromise.
Report privately
Email security@papertrader.app with the affected URL or feature, clear reproduction steps, impact, and a safe way to contact you. Do not include seed phrases, private keys, passwords, live session tokens, or personal data that is not necessary to understand the issue.
Safe research
Do not access, change, retain, or disclose another person’s data; degrade the service; use social engineering; perform denial-of-service testing; or demand payment. Stop testing and report promptly if you encounter personal data or gain unintended access.
What happens next
PaperTrader will acknowledge reports when possible, assess severity, contain active risk, preserve necessary evidence, and share reasonable status updates. A suspected personal-data breach enters the documented breach procedure, including the applicable 72-hour regulatory assessment.
Account compromise
If you believe your account is compromised, state that clearly in the subject line. Change your PaperTrader password and secure the associated email account. PaperTrader never needs your seed phrase or private key.