Platform Protection
Security
GTT B2 uses authenticated access, role checks and protected transport to help secure member and administrative functions.
Access controls
Private account and administrative areas require authenticated sessions. Administrative endpoints enforce role authorization, and members may control only the account functions permitted to their identity.
Authentication
The platform supports its existing password flow and Google OpenID Connect. Google sign-in uses server-side token validation, state and nonce checks. New registrations remain subject to administrator approval.
Transport and browser security
Production traffic uses HTTPS. Security headers restrict framing, content sources, browser permissions and referrer information. Authentication secrets and service credentials are not intentionally embedded in public frontend code.
Responsible access
Never share passwords, Google credentials, trading credentials or access tokens. If you suspect unauthorized access, stop using the affected session and contact the administrator responsible for your account.
