TradeClaw

Open-source AI market intelligence for traders who prefer evidence over noise.

Self-hosted by default

Product

  • Dashboard
  • Screener
  • Backtest
  • Track record
  • Live demo

Transparency

  • What we tested and killed
  • Methodology
  • Why long-term
  • Open data
  • Calibration

Resources

  • Blog
  • Docs
  • API reference
  • How it works
  • FAQ
  • Glossary

Community

  • Discord
  • Weekly digest
  • Contribute
  • Contributors
  • Sponsors

Open source

  • GitHub repo
  • Star history
  • Self-host guide
  • Security
  • Data freshness
  • Roadmap

© 2026 TradeClaw. MIT licensed.

Terms|Privacy|Trading involves risk. Signals are informational only and are not financial advice.
DashboardScreenerCopilotTrack Record
Not independently assessed

Security posture

This page documents controls declared in the repository. TradeClaw has not completed an independent OWASP assessment, penetration test, or certified dependency audit, so no compliance grade or security score is claimed.

Assessment scope

The OWASP Top 10 categories below are review areas, not pass/fail results. Each remains unassessed until evidence from a dated review is published.

A01Broken access controlNot assessed
A02Cryptographic failuresNot assessed
A03InjectionNot assessed
A04Insecure designNot assessed
A05Security misconfigurationNot assessed
A06Vulnerable and outdated componentsNot assessed
A07Identification and authentication failuresNot assessed
A08Software and data integrity failuresNot assessed
A09Security logging and monitoring failuresNot assessed
A10Server-side request forgeryNot assessed

Declared response headers

These values mirror the application configuration. They are not a live probe of a deployed reverse proxy, CDN, or browser response.

X-Content-Type-Options

nosniff

X-Frame-Options

SAMEORIGIN

Referrer-Policy

strict-origin-when-cross-origin

Permissions-Policy

camera=(), microphone=(), geolocation=(self)

Content-Security-Policy

Report-only policy set by middleware

Source review

Review the repository and deployment configuration directly.

Self-hosting

Docker Compose is available for deployments you operate.

Disclosure

Report suspected vulnerabilities through GitHub Security Advisories.

Report a vulnerability Security policy JSON assessment status