Trust and safety
Security
Imperium Trader can send real orders to your broker account. This page explains where secrets are stored, which network path each request takes, what can create a follow-up order, and how to verify a download.
1. What is stored, and where
| Data | Stored where |
|---|---|
| Broker API key and secret | OS-protected local storageSaved on your computer using its protected credential storage. Imperium Store does not store or back them up. |
| Broker login, PIN and TOTP | Your brokerYou authorize through the broker's own flow. Imperium Trader does not ask you to save these credentials. |
| Positions, orders, P&L, charts and settings | Local application filesKept on your computer for the platform to use. Imperium Store has no cloud sync for this trading data. |
| Store account, access and purchase records | Imperium Store and SupabaseYour email, authentication record, purchases and access dates are kept so you can sign in, verify access and re-download. Your Imperium app password is handled by Supabase Auth and is not readable back as plain text. |
| Card, UPI and net-banking credentials | RazorpayEntered directly with the payment processor. Imperium Store receives payment status and reference details, not the payment credential itself. |
2. Direct and static-IP broker paths
Default path. Market data and non-order broker API requests connect from the platform on your computer to your broker. When the static-IP option is off, order requests use this direct path too.
Optional static-IP path.When enabled for a supported broker, place, modify and cancel requests travel through an encrypted SSH tunnel to a cloud VM that you create and operate under your own cloud account. The broker sees that VM's fixed public IP.
That VM is not an Imperium server. The relay does not persist or log your broker credentials. Cloud-provider pricing, free-tier limits, uptime and availability are controlled by the provider and may change under its terms.
You can revoke an API key in your broker dashboard at any time. Imperium Trader does not ask for your broker password, PIN or TOTP secret.
3. Online access verification
At sign-in, the platform checks your email address and Imperium app password with Imperium Store and confirms that your account has paid access. An internet connection and the Store's licence service are therefore required at sign-in.
This access check does not send Imperium Store your broker keys, orders, positions or P&L. Broker traffic follows the connection paths in section 2.
4. Which actions can send orders
Imperium Trader does not select a trade or create a new entry autonomously. An order that opens a position begins with your action in the app; there is no cloud service choosing trades after the app closes.
Once you configure them, stoploss, target and trailing-stop rules can send follow-up exit orders while the app is running. The trade copier can also send corresponding follow-up orders to sub-accounts you configured. Those are automated consequences of your settings, so monitor broker order status and keep an independent exit method available.
Kaviarasu Murugan cannot sign in to your broker account, choose a trade for you or move your funds. Trading decisions and risk remain yours.
5. Windows signing and update verification
The current Windows build is not code-signed. Microsoft Defender SmartScreen may therefore display an Unknown Publisher warning. This is disclosed before purchase so the warning is not a surprise.
Download Windows and Linux builds only from the Purchases page while signed in to this Store. At present there is no publisher code signature, published checksum, or in-app cryptographic update verification. The Store download is the only supported authenticity path; do not install a copy received through a message, file-sharing site or third party.
The platform can announce that an update is available, but installation still begins with a fresh download from your Purchases page.
6. Brokers and payments
Imperium connects through each broker's own official trading API, using API keys you generate in your broker account. Broker names and logos indicate compatibility only. Imperium Store is not affiliated with, endorsed by, or an official partner of any broker.
Supported connections are Zerodha, Upstox, Angel One, Dhan, Fyers, Groww and Alice Blue. Each uses the broker's API under your own credentials and remains subject to that broker's terms.
Razorpay processes payments. Card numbers, UPI PINs, CVVs and net-banking credentials are entered with Razorpay and do not reach Imperium Store. See the Privacy Policy.
7. Service dependencies
Direct broker traffic depends on your computer, network and broker. The optional static-IP path additionally depends on your cloud VM and provider. Imperium Store does not operate that relay.
Licence verification and Store downloads do depend on Imperium Store remaining available. This is the trade-off for purchase verification and is stated here rather than hidden. Access can also be interrupted by maintenance, broker outages, cloud-provider outages or local connectivity problems.
8. Report a security issue
If you find a vulnerability or see unexpected credential handling, contact me directly. You can also read more about the operator on the About page.
Both channels reach me personally. Security reports get priority.