Special Announcement! Futures Trading is coming to Tradier. Join the waitlist today to be notified as soon as it launches. Join the Waitlist
Tradier is a technology-focused, cloud-based financial services platform and brokerage API company headquartered in Charlotte, North Carolina. As a member of FINRA and SIPC, Tradier provides a comprehensive suite of REST-based APIs that power trading applications, platforms, and tools for developers, fintech companies, registered investment advisors, and individual traders.
Our platform enables secure access to trading capabilities for stocks, options, ETFs, and futures, alongside real-time and historical market data through both request/response and streaming interfaces. Tradier serves as an innovation springboard for the fintech community, allowing businesses and developers to integrate brokerage services, execute trades, and access market data without building costly infrastructure.
The security of our platform, our users' accounts, and their financial assets is our highest priority. We welcome collaboration with the security research community to identify and address vulnerabilities in our systems.
This Vulnerability Disclosure Program (VDP) provides security researchers with a clear framework for responsibly reporting security vulnerabilities discovered in Tradier's systems. We appreciate the efforts of the security community and are committed to working with researchers to protect our users and maintain the integrity of our platform.
Thank you for helping us keep Tradier and our users safe!
The following targets are in scope for this program:
Web Applications:
This covers all frontend and backend components of Tradier's web applications, including user interfaces, APIs, and authentication systems. Note: Third-party services integrated into our web applications are OUT OF SCOPE unless the vulnerability directly impacts Tradier's systems.
tradier.comweb.tradier.com (including p-be-web.tradier.com, etc.)auth.tradier.com (including p-be-auth.tradier.com, etc.)developer.tradier.com (including p-be-developer.tradier.com, etc.)Desktop/Mobile Applications:
API:
api.tradier.comwss://ws.tradier.comstream.tradier.comTo ensure the safety and integrity of our production systems and protect our users, researchers must adhere to the following restrictions:
Financial Activities:
Authentication & Credentials:
Leaked Credentials:
Automated Testing:
Data Protection:
Strictly Prohibited:
Market Hours:
The following issues are considered out of scope for this program and should not be reported:
When conducting security research on Tradier systems, please keep the following in mind:
We are particularly interested in high-quality reports related to the following vulnerability categories:
Tradier will not pursue legal action against security researchers who conduct research in good faith and in accordance with this policy. Good-faith security research conducted under this policy is considered authorized activity.
We will not pursue legal action against researchers who:
Please use the form below to submit your vulnerability report. Do not attempt to contact Tradier employees directly or through other channels.
Tradier
Tradier Inc.
Tradier Brokerage Inc.
Member FINRA/SIPC.
3420 Toringdon Way, Suite 300
Charlotte, NC 28277
Phone: 980.272.3880
Email: service@tradierbrokerage.com