Small data footprint
Security
TickerHum currently requires no account, stores no password, connects to no brokerage or bank, and asks for no portfolio credentials.
Current safeguards
- HTTPS encrypts site and API traffic.
- Strict input validation, rate limits, bounded requests and upstream timeouts protect the public API.
- Browser security policies restrict scripts, framing and sensitive device capabilities.
- Secrets remain on the server; production browser bundles contain no private API keys.
Report a vulnerability
Please send a clear description and reproduction steps to quantlearninglab@gmail.com. Do not access other people’s data, degrade availability or publicly disclose an unresolved issue. Our machine-readable policy is at /.well-known/security.txt.