How we protect your infrastructure and credentials.
Each customer receives an isolated Windows VM with allocated CPU, memory and storage. Customers do not share an operating-system environment or trading-terminal installation. These virtual machines are deployed within secure virtual networks with strict firewall rules, exposing only the necessary ports for connectivity and remote management.
Trading-platform credentials are encrypted before storage in Calamari's segregated credential vault. Credentials are never stored in plaintext. Administrative access is restricted, time-limited and logged. Customers can rotate credentials at any time. Credentials are permanently deleted upon service cancellation.
Additional details:
Calamari continuously monitors supported VM and terminal health signals while the service is operational, including nights and weekends. Monitoring systems operate outside your VM. External heartbeat monitoring means that if your VM crashes, freezes, or loses network connectivity, our systems detect the failure independently and can initiate automated recovery procedures, rather than relying on an internal agent that would fail alongside the VM.
Our LiveView feature allows you to view your MT4/MT5 terminals from your browser. This is a secure, real-time stream. We do not record, store, or retain screenshots or video of your terminal sessions. The data is transmitted securely via TLS and exists only while your LiveView session is active.
Staff do not have standing access to your VM. Temporary support access requires your explicit authorization before any session begins. All access events — including the timestamp, purpose, and personnel involved — are logged and continuously monitored. Calamari does not inspect, analyze, copy or reuse your trading strategy. Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) are required for all administrative access.
When you cancel your Calamari Trading service, your infrastructure is immediately queued for decommissioning. We retain your encrypted data and virtual machine snapshots for 30 days post-cancellation to allow for account recovery if you change your mind. After 30 days, or immediately upon your explicit request, all virtual machines are destroyed and all associated data, including credentials and trading history, are permanently wiped from our databases.
We do not sell your data. We do not use your trading data for advertising, signal generation, or any proprietary trading purposes. We do not disclose your trading data to other traders. Limited data may be processed by our infrastructure providers solely to operate Calamari, subject to strict contractual confidentiality and security obligations.
If you believe you have discovered a security vulnerability in our platform, please report it to us immediately at security@calamaritrading.ai. We take all reports seriously and will investigate promptly.