Security, sessions and your data
Two-factor auth, single-use sessions, a tamper-evident audit chain and one-click erasure — the platform's security posture, explained.
2026-10-07 · SIDDANI DOCS
Everything here is read-only by design, but reading is still personal. The account center is the control room: two-factor authentication, active sessions, data export and one-click erasure — all functional, none decorative.
Two-factor authentication
TOTP via any authenticator app: scan the QR, enter the six-digit code, and the account demands the code at every sign-in. Deployment operators can additionally enforce TOTP for all privileged accounts platform-wide.
Sessions
Every device holding a valid session is listed with its browser, platform and last use. Sessions use short-lived access tokens and single-use refresh rotation with reuse detection — a replayed refresh token kills the family. Sign out everywhere is one button.
The audit chain
Registrations, sign-ins, admin actions, syncs and deliveries commit to a hash chain — any edit or deletion breaks it visibly. Your own security feed shows the same events with their outcomes.
Your data
GDPR export (Art. 15/20) downloads everything as JSON; erasure (Art. 17) removes the account, connections and trading data within 30 days — audit records stay anonymized so the chain keeps verifying. Support tickets are purged with the account.
What Siddani holds
Read-only API keys in the vault, deal data, derived metrics, journal entries you wrote. No withdrawal permissions ever, no file uploads, no manual trade entry — the constraints are the security model.
Read-only enforced · vault-sealed keys · hash-chained audit · one-click erasure. Security is the product constraint, not a feature list.