Security
Security designed into every boundary.
AITS treats identity, credentials, permissions, orders, executions, and audit data as separate high-trust concerns.
Protected sessions
Opaque tokens stay in secure HTTP-only cookies and can be reviewed or revoked per device.
Independent authorization
Every privileged operation is checked by the API. Admin access requires MFA.
Encrypted broker secrets
Credentials never reach the browser and are encrypted through a replaceable secret-provider abstraction.
Fail-closed trading
Unknown risk, broker, market-data, account, or kill-switch state blocks new orders.
