GUIDE 8 · SECURITY · 10 MIN

Security, sessions and your data

Two-factor auth, single-use sessions, a tamper-evident audit chain and one-click erasure — the platform's security posture, explained.

2026-10-07 · SIDDANI DOCS

Everything here is read-only by design, but reading is still personal. The account center is the control room: two-factor authentication, active sessions, data export and one-click erasure — all functional, none decorative.

1

Two-factor authentication

TOTP via any authenticator app: scan the QR, enter the six-digit code, and the account demands the code at every sign-in. Deployment operators can additionally enforce TOTP for all privileged accounts platform-wide.

2

Sessions

Every device holding a valid session is listed with its browser, platform and last use. Sessions use short-lived access tokens and single-use refresh rotation with reuse detection — a replayed refresh token kills the family. Sign out everywhere is one button.

3

The audit chain

Registrations, sign-ins, admin actions, syncs and deliveries commit to a hash chain — any edit or deletion breaks it visibly. Your own security feed shows the same events with their outcomes.

4

Your data

GDPR export (Art. 15/20) downloads everything as JSON; erasure (Art. 17) removes the account, connections and trading data within 30 days — audit records stay anonymized so the chain keeps verifying. Support tickets are purged with the account.

What Siddani holds

Read-only API keys in the vault, deal data, derived metrics, journal entries you wrote. No withdrawal permissions ever, no file uploads, no manual trade entry — the constraints are the security model.

Start free All guides

Read-only enforced · vault-sealed keys · hash-chained audit · one-click erasure. Security is the product constraint, not a feature list.