Security

A safer product boundary starts with split apps and visible consent.

The commercial Client is designed to avoid carrying internal customer-management tools, while internal operations stay operator-only.

Security model

Separate apps

Commercial Client and internal operations are separate builds. Customer-management tools are not shipped to customers.

Provider keys

Customer provider API keys should use secure storage and must not be placed in localStorage.

Learning consent

AI Coach, sandbox learning, review feedback, and learning-library growth require explicit consent.

No live orders

The current Client is research and paper simulation only.

Admin data boundary

Customer, order, KEY, and audit administration stays inside the internal app and server-side controls.

CSP and API hardening

Production builds should enforce CSP, CORS allowlists, signed tokens, and secure password hashing.

Trading safety

Research and paper simulation only

CCOR AI is designed for market research, paper simulation, risk review, and decision support. It does not constitute investment advice, does not guarantee returns, and the current Client does not submit live trading orders.