Security Overview
Version COMMERCIAL_V1_EN_2 ยท Last updated 23 August 2026
A concise, non-exhaustive description of verified Commercial V1 safeguards and user responsibilities.
Andres Plaza, operating TradingWaves Journal in Spain
Full service-provider details are available in the Legal Notice.
Service safeguards
TradingWaves Journal uses modern password hashing for new and updated passwords, signed expiring verification and recovery flows, CSRF protection for sensitive actions, session rotation and expiry controls, bounded remembered sign-in, authorization checks and private server-side configuration for sensitive runtime values.
Public application traffic is intended to use HTTPS. Payment-card entry is handled by Stripe-hosted payment surfaces; TradingWaves Journal does not claim to store raw card details.
Limits
This overview is not a certification, audit report or guarantee that every attack or interruption can be prevented. It intentionally omits secrets and exploit-sensitive operational details.
Your responsibilities
Use a unique password, protect access to your email and device, log out of shared devices and keep journal exports or imported files secure. Contact support@tradingwavesjournal.com if you suspect unauthorized account activity.
Reporting a concern
Security concerns may be reported to support@tradingwavesjournal.com. Include only the information necessary to describe the concern and do not send passwords, payment-card details or other secrets. Privacy incidents may also be reported to privacy@tradingwavesjournal.com.