Compliance & Safety
How MAT handles your data, your trades, and your money.
Paper trading only
MAT MVP does not place real orders. Every brain is hard-locked to mode = paper. Live execution is not available and is not coming until risk controls, broker consent, and a kill switch are independently audited.
No card data, PCI-DSS not in scope
MAT MVP does not collect, transmit, or store any cardholder data, PAN, CVV, or broker API credentials. If billing is added later, payments will be processed by a PCI Level 1 provider (Stripe/Paddle Checkout) so that cardholder data never touches MAT servers (SAQ-A scope).
Security posture (ISO 27001 readiness)
All data is stored with row-level security: signed-in users can only read or write their own brains, trades, reviews, chat history, and memory. Public brains and the leaderboard are read-only. Passwords are checked against the Have-I-Been-Pwned breach list at signup. Secrets and AI keys live server-side only.
Auditability
Every AI call is logged to agent_runs with input/output summary, latency, and tool actions. Every score change and rule edit is logged to audit_log. AI-generated trade ideas always include risk context and a "not financial advice" disclaimer.
MAT is an educational paper-trading and AI training platform. Nothing in MAT is investment advice, a solicitation, or a guarantee of profit. Trading involves substantial risk of loss.
