QuantumCat/Security & privacy

Security & privacy

Software you run. Not a service that holds you.

QuantumCat is a desktop application. Your keys, your tape and your trading record stay on your machine, and your orders go straight to the broker you already trust. Here’s exactly how.

Your machineQuantumCat

Keys encrypted on your own disk. Every tick recorded locally. The ticket, bots, Pulse and JARVIS all run here.

official API
your login
Your brokerZerodha · Dhan
Angel One · Groww

Executes every order under your own credentials. Your money and securities never leave it.

exchange
member
The exchangeNSE · BSE · MCX

Where the order fills — through the member you already trust.

No QuantumCat server in the order path. The licensing service knows an account exists — never your trades, positions or P&L.

The guarantees

What stays with you — and why.

Each of these is enforced in the product, not promised in a policy.

Credentials

An encrypted vault on your own disk

API keys, secrets and session tokens are sealed with AES-256-GCM inside QuantumCat’s own data folder. They are never synced and never sent to us. Your broker password is only ever typed on your broker’s own login page.

Orders

Straight from your machine to your broker

Every order leaves your machine for your broker’s official API under your own login. There is no QuantumCat server in the order path to fail, throttle or see it.

Your data

Ticks, journals and backtests stay local

The terminal records the tape it streams to your own disk from day one — the archive behind replay and backtests. Journals, bots and research live beside it.

What we see

An account, never a book

The only QuantumCat service is licensing. It knows an account exists and whether it’s active — never your trades, positions, balances or P&L.

Updates

Signed, verified, notarized

Every update is signature-checked before it installs. Mac builds are Developer ID signed and notarized by Apple; the app refuses a package whose signature doesn’t match.

AI

JARVIS can’t reach your keys

JARVIS runs on your own ChatGPT plan. The tools that could read credentials or change risk limits aren’t in its toolbox, and it stages orders for your confirmation by default.

The static-IP rule

SEBI’s IP rule, handled.

Since 1 April 2026, brokers accept API orders only from an internet address you’ve registered with them. Market data works from anywhere — only order placement is gated.

  • Guided setup for each broker — one click on Dhan, copy-paste steps for Zerodha and Angel One
  • Drift warnings when your connection’s IP no longer matches what your broker saw
  • Static IP options explained: from your ISP, or your own fixed-IP relay
Read the setup guide
QuantumCat's broker connection setup. Broker setup · real build

Private by design. Fast by nature.