Security Center
Customer Security and Anti-Fraud Protection
The prevalence of online fraud and identity theft poses serious risks.
At TradeStation, protecting the safety and security of your accounts and identity is of the utmost importance. As your partner in online security, we leverage our technologies and operational best practices in order to keep your valuable accounts and private information safe. Of course, there is much that you can do to better protect yourself online as well.
How We Protect You
We know that TradeStation customers need to be able to access their accounts safely and securely online from a variety of devices while at home, the office, or on the go. TradeStation uses secure technologies and other internal measures to ensure that every time you access your account, you can do so with confidence. Here are just a few ways in which we work to keep your account secure.
Unique Usernames and Strong Encrypted Passwords
To aid in the prevention of unauthorized access, all customers are required to select a unique username and a strong password when you open your first account. Passwords are required to meet minimum strength requirements, including overall length and a mixture of letters, numbers and special characters.
Strong Customer Login Verification Online
Whenever you attempt to log in from a web browser on an unknown device, you will be asked to answer one of your enhanced security questions after successfully entering your username and password to further validate your identity.
Session Timeouts
Our websites and mobile trading applications include an integrated timeout feature. After a period of inactivity, you will automatically be logged out to ensure the safety of your account and personal information.
Login Attempt Limitations
To deter possible threats from cybercriminals by way of scripted or computer-based attacks, we limit the number of failed concurrent login attempts permitted for any single user or from any specific device.
Extended Secure Website Verification
Whenever you are asked to enter your TradeStation login credentials online, it is critical that you can easily verify that the website is owned and operated by TradeStation. To make this possible, we have deployed extended verification security certificates (EV SSL) to our websites.
How You Can Protect Yourself
Identity theft and identity fraud refer to crimes in which someone wrongfully obtains and uses another person’s personal information in order to commit some form of fraud or deception, typically for economic gain. The consequences of identity theft and identity fraud can be very serious, often resulting in significant out-of-pocket expenses, a damaged credit rating and even denial of credit. It is therefore critical that you take measures to protect your money and reputation.
Monitor Your Account
Regularly review your account balances and positions. Take notice if statements do not arrive on time. Be sure to open in a timely manner all online and offline communications from the financial institutions with which you do business. Report suspected fraud immediately.
Maintain Accurate Account Information
In the event that we detect unusual or suspicious activity relating to your account, it is critical that we are able to contact you immediately. Should your contact information change, log in to the TradeStation Client Center and update your information (e.g., telephone numbers, email address, mailing address).
Username and Password Recommendations
- Never share your username or password with anyone.
- Don’t re-use usernames or passwords between different accounts
- Never use sensitive information as part of your username or password
- Avoid easy-to-guess or predictable passwords, such as those containing your name, birthday, phone number, pets’ names or Social Security number.
- Keep your passwords and reminders in a safe place. Print them and store them in a safe location in your home, or consider purchasing a software password-keeper solution.
- Consider changing your passwords periodically.
Two-Factor Authentication
Two-Factor Authentication is a security feature available in the Client Center that adds an extra layer of protection when accessing your TradeStation accounts. Once this feature is enabled, when you login from an untrusted device you will either be asked to approve the log in request from your mobile device, or you will be asked to enter a 6-digit verification code to verify your identity.
Avoid Phishing Attacks
Phishing is when someone attempts to steal personal or financial information by impersonating a trustworthy entity. Phishing often begins with an email or other communication asking for sensitive information, such as your username, password or other sensitive account information.
- Only enter your credentials when you are on a website that ends with .tradestation.com.
- Use search engines to find the “right” website for the business you are seeking. Search engines will correct misspellings in providing recommended results.
- Never enter information into an unsecured website.
- Be skeptical of emails peddling offers or making claims that seem too good to be true. Ask yourself if you have a real business relationship with the sender.
- Test your phishing knowledge and learn more about how to spot potential threats.
Avoid Using Unsecured Wireless (Wi-Fi) Networks
In order to make network access easier, public Wi-Fi hot spots often turn their security off. This means that any information you send from this hot spot likely will not be encrypted and could be intercepted or altered by a criminal. To avoid automatically joining these networks, change your device settings to only allow connections to secured networks, or simply disable your Wi-Fi adapter when not in use.
Do Not Share Your Account Number with Anyone
You should only provide your account number if you have directly contacted a trusted TradeStation representative for assistance, or if you must provide the account number to a known and trusted third party in order to authorize a desired action, such as transferring funds to or from another financial institution.
Request a Free Annual Credit Report
A free credit report is available to all U.S. residents every 12 months from the top three nationwide consumer credit reporting agencies: Equifax, Experian, and TransUnion. For more information, visit http://annualcreditreport.com/.
Consider Enrolling in an Identity Monitoring and Theft Prevention Service
These providers offer real-time monitoring of your identity as well as your credit, and may be able to prevent or alert you to potential threats as they occur.
Vulnerability Disclosure Policy
TradeStation is deeply committed to maintaining the security of our systems and protecting confidential and personal information from unauthorized disclosure.
While we appreciate you bringing security issues to our attention, please be advised that performing security testing against our systems without our written authorization is unlawful and could result in civil or criminal legal actions. Security researchers are requested to only engage in security testing activities when authorized.
If you have inadvertently found a vulnerability in one of our products or services and would like to report it to our security team, you can let us know by sending an email to ClientExperience@TradeStation.com and including the following information in your vulnerability report:
- A description of the nature of the vulnerability identified and how it was detected, including any information regarding exploitation of the vulnerability.
- The exact steps for us to follow to reproduce the issue.
- Screenshots and URLs to explain your findings
Once we receive the information, we will perform a thorough review and respond in a timely manner.
Please be aware that TradeStation does not offer rewards or “bug bounties” for vulnerability reports.
ID3008831D0723