Legal

Security

Last updated: August 6, 2026

Fuselit connects to your brokerage account and places real orders, so the security of that connection is the most important thing we build. This page describes the controls that protect your account and your data, what you can do to harden your own account, and how to report a vulnerability to us.

Your money never touches Fuselit. Your cash and securities stay in your own brokerage account, held by your broker rather than by us. We hold no customer funds, and the brokerage connection you grant does not let us deposit or withdraw money — deposits and withdrawals happen only at your broker, under your own login.

1. Your brokerage connection

There are two ways to connect a brokerage account, and both are designed so that the smallest possible amount of secret material reaches us:

Either way, the connection is scoped to reading your account and market data and to placing and managing orders. One Fuselit account maps to one brokerage account at a time, and you can disconnect from Settings whenever you want; disconnecting deletes the stored credential.

2. Encryption

3. Account security

4. Infrastructure

5. Payments

Subscription payments are processed by Stripe. Card details are entered directly into Stripe's hosted checkout and never pass through Fuselit's servers — we store only limited billing metadata such as plan, status, and the last four digits of the card. We are not able to charge a card outside the subscription you signed up for.

6. Third parties we rely on

We keep the list of vendors that can touch your data deliberately short:

What each of them receives, and why, is described in the Privacy Policy.

7. What we do not claim

We would rather be precise than impressive. Fuselit is an independent, small operation. We do not currently hold a SOC 2, ISO 27001, or PCI attestation, and we have not undergone a third-party penetration test. We do not run a paid bug bounty. No system is perfectly secure, and no set of controls can eliminate the risk of a compromise — the measures above reduce it, they do not remove it. If any of this changes, this page changes with it.

8. What you can do

9. Reporting a vulnerability

If you believe you have found a security issue, email [email protected] with the subject line "Security" and enough detail to reproduce it — the affected URL or endpoint, the steps you took, and what you observed. We aim to acknowledge reports within three business days and to keep you updated until the issue is resolved.

We will not pursue legal action against researchers who report in good faith and who:

We do not offer monetary rewards, but we are glad to credit you once a fix has shipped, if you would like that.

10. If something goes wrong

If we become aware of a breach affecting your personal information or your brokerage credentials, we will notify affected users without undue delay, describe what happened and what data was involved, and tell you what to do — including revoking the brokerage connection and rotating credentials. Where the law requires notification of regulators or a specific timeline, we will follow it.

11. Contact

Security questions, or anything on this page that you would like explained in more detail: [email protected].

Privacy Policy · Terms of Service · Risk Disclosure · Back to home