1. Our approach
Raiverr Digital is a company established in Malaysia. We use administrative, technical, and organisational measures intended to reduce security risk for Telegram To MT4/MT5 Copier. Security is a shared responsibility across our hosted Service, your browser and devices, the Windows client or VPS, Telegram, MetaAPI, MetaTrader, and your broker environment.
No system is completely secure. This page describes practices and responsibilities; it is not a guarantee that an incident, outage, data loss, account compromise, or incorrect trade will never occur.
2. Website and account controls
The production website uses HTTPS to protect data in transit between supported browsers and our web service. Website passwords are stored using one-way password hashing rather than as readable website passwords. Production session cookies use Secure, HttpOnly, and SameSite attributes, and sensitive browser forms use anti-forgery protections where applicable.
Selected authentication, API, contact, and high-risk endpoints use input validation, request throttling, expiring tokens, or account and ownership checks. Browser security headers include content-loading restrictions and permissions policies intended to reduce exposure to selected injection and browser-feature risks.
These controls reduce risk but do not make stolen credentials, unsafe devices, social engineering, browser extensions, or third-party compromise harmless.
3. Connection credentials and trading data
Copier features may require Telegram connection data, MetaAPI credentials, API tokens, broker or server identifiers, and MT4/MT5 account data. Some connection secrets must remain usable by the Service to perform the actions you request. MetaAPI tokens stored by the dashboard are protected at rest using authenticated encryption. We seek to limit access and retention to operational needs, but you should treat every connected token and session as sensitive.
Use separate credentials where a provider supports them, grant the least access needed, rotate credentials after suspected exposure, and disconnect services you no longer use. Never send a password, Telegram session string, MetaAPI token, payment-card number, or broker credential through ordinary email or live chat.
4. Payments
Stripe currently processes checkout and recurring payments. Payment-card fields are generally collected in Stripe-hosted checkout rather than by our application. Stripe webhook signatures are verified before payment events are processed. We receive transaction and subscription details needed to provide access, reconcile payments, handle refunds or disputes, and meet recordkeeping obligations.
Stripe is a separate provider with its own security and privacy practices. Raiverr Digital remains responsible for securing the payment and subscription data held in our systems.
5. Service operations
Operational safeguards may include controlled administrative access, environment-specific secrets, application and security logging, monitoring of selected service events, backups and recovery procedures, update and dependency review, and investigation of suspicious activity. The exact controls can vary by component and are reviewed as the Service changes.
Logs and backups are themselves protected as operational data. We avoid promising a fixed recovery time, uninterrupted monitoring, or that every event will be detected.
6. Windows client, VPS, and MetaTrader
You control the security of the Windows computer or VPS and MetaTrader environment used for local execution. Keep the operating system, Windows client, MetaTrader, expert advisors, and security software current. Download installers and expert advisors only from an authenticated Raiverr Digital page, verify prompts before installation, restrict remote access, and use a trusted network.
Protect MetaTrader data folders and configuration files, limit who can access the desktop or VPS, and review WebRequest URLs and expert-advisor permissions. Selecting the wrong execution mode or running conflicting cloud and local paths can create operational risk even when no security control has failed.
7. Your security responsibilities
Use a unique, strong password and secure the email account used for recovery. Do not share sessions, API tokens, licences, or account access outside authorised personnel. Regularly review connected channels, accounts, execution modes, symbols, risk limits, and recent logs, and remove connections that are no longer needed.
Test configuration changes on a demo or otherwise limited-risk environment before live use. Revoke third-party credentials and contact us promptly if you suspect compromise. Keep independent records and safeguards appropriate to the financial risk you choose to take.
8. Reporting a vulnerability
Submit a Security report through our online contact form. Begin the message with Security report and include the affected URL or component, reproducible steps, impact, and a safe proof of concept. Do not include personal data or live credentials. If the form is unavailable, contact support@telegramtomt5copier.com manually.
Do not access another user's account or data, place or alter trades, cause service disruption, use destructive testing, exfiltrate data, demand payment, or publicly disclose an unresolved issue. We do not currently promise a bug bounty, payment, or safe-harbour programme. We will review good-faith reports and may ask for more information.
9. Suspected incidents
If we identify a suspected security incident, we may investigate, contain affected access, preserve relevant records, reset sessions or credentials, suspend integrations, restore components, and work with providers or authorities. We will notify affected people or regulators when required by applicable law.
If you believe your own account is affected, stop automated execution if it is safe to do so, revoke relevant third-party tokens, secure your email and device, review broker activity, and contact us with the subject Urgent account security.
10. Scope and updates
These practices apply to systems operated by Raiverr Digital. Telegram, MetaAPI, Stripe, MetaTrader, brokers, hosting providers, analytics providers, and live-chat services operate separate systems under their own terms.
We may update this page as threats, architecture, providers, and controls change. The version and updated date above identify the current statement. Security questions can be submitted through our online contact form or sent manually to support@telegramtomt5copier.com.