Is OmenSyncer safe to use?
How OmenSyncer protects your accounts: credentials encrypted before they are stored, OAuth where brokers offer it, and the limits of what it can do.
Updated
Yes. OmenSyncer places and manages orders through your broker's own API, encrypts your login details at rest, and has no way to move or withdraw money.
Your credentials are encrypted
Broker logins and tokens are stored with AES-256 (GCM) encryption and decrypted in memory only at the moment an order is placed. They are never written to logs. A copy of the database on its own is unreadable without the separate encryption key.
It places trades, nothing more
OmenSyncer uses the same API your trading platform does, and it can only take trading actions:
- Place, modify, and cancel orders
- Read positions and account state to keep followers in sync
- Flatten positions when you ask it to
There is no deposit, withdrawal, or transfer capability anywhere in OmenSyncer. It cannot send money or change your banking details, because your broker never exposes those actions to the API.
You stay in control
You choose which connections are active, which accounts copy, and at what size, and you can turn any of it off at any time. For which parts of a trade OmenSyncer decides versus your broker, see What we control (and what your broker does).
