Access and Account Security
Access, permissions, and activity—made explicit.
Taronzo organizes account security around authenticated sessions, scoped permissions, workspace separation, recorded activity, and operational restriction states.
Five boundaries between a login and an order.
A defense-in-depth model that protects your operations at every stage—from initial authentication down to individual order routing.
Identity verification
Hardware-bound multi-factor authentication and strict device verification.
Session validation
Context-aware tokens binding access to device, IP, and activity state.
Permission evaluation
Granular scope limits per API key, sub-account role, or operator.
Workspace boundary
Logical separation of account data, positions, and execution contexts.
Audit and restriction state
Immutable activity logging and pre-trade exposure guardrails.
Each boundary operates independently. A compromise at one layer does not automatically grant access through the next.
See who accessed what, when, and under which permissions.
Review session activity, permissions, security events, account states, and operational controls from one consistent security view.
Immediately cancels all open orders and revokes all API sessions.
Session validity, reauthentication, and termination.
Every authenticated session is validated continuously. Critical actions require reauthentication. Inactive or suspicious sessions are terminated automatically.
Continuous Validation
Session tokens are verified against device context, IP patterns, and activity signatures throughout the session lifecycle.
Forced Reauthentication
Modifying security settings, whitelist entries, or high-impact configurations requires fresh authentication.
Roles, approval boundaries, and restricted operations.
Not every authenticated user can perform every action. Permissions define what is allowed, what requires approval, and what remains blocked entirely.
Scoped Roles
API keys and user accounts receive only the permissions required for their specific function.
Restricted Operations
Certain configuration changes and withdrawal paths require multi-step approval or are disabled by default.
Workspace separation, activity records, and emergency restrictions.
Data, orders, and balances belong strictly to their workspace context. Every significant action is recorded. Emergency restrictions can halt activity when anomalies are detected.
Workspace Boundaries
Algorithms, positions, and configuration in one workspace cannot interact with or access data from another.
Emergency Restrictions
Automated detection of anomalous activity can trigger immediate trading suspension and operator notification.
What the security model covers—and what it does not promise.
Trust requires honesty. Taronzo Terminal is designed to significantly reduce operational and account risks through engineering best practices. We focus on practical, rigorous, and verifiable security controls to protect our users.
What Taronzo Does
- Hardware-bound multi-factor authentication (e.g. YubiKey)
- Strict logical isolation of workspace and account data
- Granular API permissions (read-only, restrict by IP)
- Immutable event logs for critical access actions
- Pre-trade risk guardrails for algorithmic routing
What Taronzo Does Not Claim
- "Military-grade" or "Bank-grade" buzzwords without context
- Unverified third-party certifications or fake badges
- Guarantees of 100% protection against all possible threats
- Hidden fees dressed up as security premiums
- Marketing claims about impenetrable systems
Questions about account security?
For security inquiries or to report a vulnerability, contact Taronzo Markets directly.