Security & privacy

Your AI. Our build room. Your Pack.

Threat model and controls are documented in the repository security model. This page summarizes user-facing boundaries — not certification claims. We do not run trades on your behalf or store broker passwords in company cloud systems.

Managed Pack builds

Compilation and bounded checks for Build Pass run on RNME-controlled Windows workers — not on your PC. You do not need Windows or MT5 before a finished Pack exists.

No broker passwords

We never store trading account passwords or place trades. MT5 login stays between you and your broker.

Optional Live Connector

After a ready Pack, the Connector on your Windows machine can send redacted telemetry for Live. It is not required for Pack delivery and binds local control to loopback by default.

Package integrity

Delivery packages include hashes for source, .ex5, report, and manifest. Verified means compiled and hashed — not profitable.

Build protocol limits

  • Schema-validated build and MCP tool inputs
  • No generic shell or unrestricted filesystem tools on the public path
  • No secrets exposure in tool results
  • Isolated workers wiped between Pack jobs

Data & privacy

We collect account, billing, build job metadata, Pack artifacts, and optional post-delivery monitoring. Logs redact passwords, API keys, and device tokens.

Privacy policy (draft)