Security
What we actually do, and what we don’t claim
Financial websites tend to describe security with adjectives — bank-grade, military-grade, fully secure. Those words are unregulated and mean nothing in particular. This page lists specific controls instead, and marks the ones not yet live as not yet live.
Login and authentication
- Password policy
- Information to be verified
- OTP on login
- Information to be verified
- Two-factor authentication
- Information to be verified
- Biometric unlock on mobile
- Information to be verified
- Failed-attempt lockout
- Information to be verified
Each row above is filled in from configuration once the control is live in production and confirmed by our engineering and compliance teams. A blank row means the control is not yet confirmed — not that it is secret.
Sessions and devices
- View active sessions
- Information to be verified
- Log out all devices
- Information to be verified
- New-device login alert
- Information to be verified
- Session timeout
- Information to be verified
Money movement controls
- Payouts to registered bank account only
- ✓ Enforced
- Third-party transfers
- ✓ Not permitted
- Bank account change process
- Information to be verified
- Withdrawal alerts
- Information to be verified
The first two rows are marked as enforced because they are regulatory requirements applying to every SEBI-registered broker, not features we invented. Money can leave your trading account only to a bank account in your own name.
Data protection
- Transport encryption (HTTPS/TLS)
- ✓ In use on this website
- Encryption of stored personal data
- Information to be verified
- Access control and audit logging
- Information to be verified
- Third-party security assessment
- Information to be verified
- Data retention policy
- See Privacy Policy on the Verify page
We will not list a certification, audit or standard here until it has been completed and we can name the assessor and the date. An unearned security badge on a broker website is a reason for less confidence, not more.
The part that depends on you
Most account compromises in Indian broking do not involve breaking into the broker. They involve persuading the customer to hand over a credential. That makes these the highest- value controls in the entire system, and they are yours.
- Never share an OTP, password or PIN with anyone
Including anyone claiming to be from Trade Grow, your bank, or a regulator.
- Never install a screen-sharing or remote-access app on request
There is no support scenario at Trade Grow that requires it.
- Use a password you do not use anywhere else
Credential reuse is how a breach at an unrelated website becomes a problem for your trading account.
- Keep your registered mobile and email current
Alerts are only useful if they reach you. Update them if you change numbers.
- Read your contract notes and ledger
An unfamiliar trade or debit is far easier to resolve in days than in months.
- Download the app only from the official store listing
Check the developer name matches our registered entity. Never install an APK sent in a message.
Know the warning signs
Our fraud awareness page lists the specific scripts used against trading customers in India, so you can recognise one when it reaches you.