TradeClaw

Open trading research for testing ideas, modeling costs, and reproducing every result.

Self-hosted by default

Evidence

  • Track record
  • Studies
  • Prospective ledger
  • Methodology
  • Open data

Lab

  • Candidate feed
  • Screener
  • Backtest

Build

  • Self-host guide
  • Documentation
  • API reference
  • GitHub

© 2026 TradeClaw. MIT licensed.

Terms|Privacy|Trading involves risk. Research candidates are not trade instructions or financial advice.
EvidenceLabBuild
Not independently assessed

Security posture

This page documents controls declared in the repository. TradeClaw has not completed an independent OWASP assessment, penetration test, or certified dependency audit, so no compliance grade or security score is claimed.

Assessment scope

The OWASP Top 10 categories below are review areas, not pass/fail results. Each remains unassessed until evidence from a dated review is published.

A01Broken access controlNot assessed
A02Cryptographic failuresNot assessed
A03InjectionNot assessed
A04Insecure designNot assessed
A05Security misconfigurationNot assessed
A06Vulnerable and outdated componentsNot assessed
A07Identification and authentication failuresNot assessed
A08Software and data integrity failuresNot assessed
A09Security logging and monitoring failuresNot assessed
A10Server-side request forgeryNot assessed

Declared response headers

These values mirror the application configuration. They are not a live probe of a deployed reverse proxy, CDN, or browser response.

X-Content-Type-Options

nosniff

X-Frame-Options

SAMEORIGIN

Referrer-Policy

strict-origin-when-cross-origin

Permissions-Policy

camera=(), microphone=(), geolocation=(self)

Content-Security-Policy

Report-only policy set by middleware

Source review

Review the repository and deployment configuration directly.

Self-hosting

Docker Compose is available for deployments you operate.

Disclosure

Report suspected vulnerabilities through GitHub Security Advisories.

Report a vulnerability Security policy JSON assessment status