TradingWaves Journal

Security Overview

Version COMMERCIAL_V1_EN_2 ยท Last updated 23 August 2026

A concise, non-exhaustive description of verified Commercial V1 safeguards and user responsibilities.

Service operator
Andres Plaza, operating TradingWaves Journal in Spain
Full service-provider details are available in the Legal Notice.

Service safeguards

TradingWaves Journal uses modern password hashing for new and updated passwords, signed expiring verification and recovery flows, CSRF protection for sensitive actions, session rotation and expiry controls, bounded remembered sign-in, authorization checks and private server-side configuration for sensitive runtime values.

Public application traffic is intended to use HTTPS. Payment-card entry is handled by Stripe-hosted payment surfaces; TradingWaves Journal does not claim to store raw card details.

Limits

This overview is not a certification, audit report or guarantee that every attack or interruption can be prevented. It intentionally omits secrets and exploit-sensitive operational details.

Your responsibilities

Use a unique password, protect access to your email and device, log out of shared devices and keep journal exports or imported files secure. Contact support@tradingwavesjournal.com if you suspect unauthorized account activity.

Reporting a concern

Security concerns may be reported to support@tradingwavesjournal.com. Include only the information necessary to describe the concern and do not send passwords, payment-card details or other secrets. Privacy incidents may also be reported to privacy@tradingwavesjournal.com.