The AI engine is offline (last seen Aug 12, 05:02 UTC). Scores are shown as of their timestamps; new theses and refreshes are queued and run the moment it returns.

Security

Last updated: July 28, 2026

Reporting a vulnerability

If you believe you have found a security issue, please email [email protected] with enough detail to reproduce it. We aim to acknowledge reports within a few days.

Please give us a reasonable chance to fix the issue before disclosing it publicly. We will not pursue legal action against researchers who report in good faith, stay within the boundaries below, and do not access, modify, or retain other people's data.

Please do not

  • Run denial-of-service, load, or brute-force tests against the live site.
  • Access, alter, or download data belonging to other users. If a bug exposes someone else's data, stop, and tell us what you saw rather than collecting more.
  • Use social engineering, phishing, or physical attacks against us, our users, or our service providers.
  • Place real brokerage orders in accounts that are not your own.

How we handle your data

Passwords are stored only as salted hashes. Brokerage access is granted by you through your broker's OAuth flow, is scoped to your own account, is encrypted at rest, and can be revoked at any time from your broker's dashboard. We never hold your funds or securities.

The site is served over HTTPS only, with HSTS and a content security policy. Requests that change data are protected against cross-site request forgery.

What this page is not

We do not currently run a paid bug-bounty program. This is a small team, and CatalystRanked is early software — we would rather hear about a problem than not, and we would rather tell you honestly that we cannot pay for it than imply otherwise.

Machine-readable contact: /.well-known/security.txt. See also our Terms of Use and Privacy Policy.