The vendor is breached
The most common failure and the least avoidable one. A database of trading logins is an unusually attractive target, and the traders in it find out last.
R4CopierEvery copy-trading service that runs in the cloud needs a working login to the accounts it trades. R4Copier runs on your machine instead, so the login never leaves it — and there is no vendor-side copy of your credentials to protect, leak, or subpoena.
Account number, server, password. Sometimes framed as an API key, sometimes as an investor login, but the substance is identical: a credential that works.
Traders hand these over constantly, and mostly nothing happens. The service works, the trades copy, and the credential sits in a database somewhere for as long as the account exists. The risk is not that the vendor is dishonest. It is that you have created an asset you cannot see, cannot audit, and cannot revoke with any precision.
MetaTrader has no per-application access token. There is no scope to grant, no permission to narrow, no key to rotate independently. There is one password per account, it does everything that account can do, and the only way to withdraw access from one holder is to change it for all of them.
None of these require the vendor to have bad intentions. That is the point — good intentions are not a control.
The most common failure and the least avoidable one. A database of trading logins is an unusually attractive target, and the traders in it find out last.
Support staff, contractors, whoever holds production database access. Most small SaaS companies cannot honestly claim otherwise, and few are asked.
Acquisitions, shutdowns and asset sales move data with them. The privacy policy you agreed to at signup is not the one that governs the buyer.
You cannot un-share a MetaTrader password from one service. You change it, every integration breaks at once, and you rebuild your setup from scratch.
A read-only login still exposes your entire position history and equity curve. That is commercially sensitive on its own, and it is often reused across accounts.
Firms generally treat account access as the trader’s responsibility. If a shared credential is misused, the rule breach lands on your evaluation, not the vendor’s.
R4Copier does not host your terminal. It attaches to the MT4, MT5 and cTrader installations already on your PC or VPS through each platform’s native bridge. When you add an account, the credential is written to your operating system’s keystore — Windows Credential Manager, macOS Keychain — encrypted by the OS under your own user account.
From that point the login exists in exactly one place: the machine you put it on. Our servers receive your licence status, your account numbers, your copy rules and the trade history the terminal has already executed, so the web dashboard has something to show you. They do not receive the password, because nothing in the copying path ever sends it.
That distinction is worth being precise about, because it changes what a breach of us would cost you. It would expose which accounts you run and what you traded. It would not expose anything that can log in. There is no such record to expose.
Test it, don’t trust it. Point Wireshark, Fiddler or your firewall’s connection log at the terminal while you add an account. The broker authentication goes to your broker. This is the useful property of an architectural claim: it is falsifiable from your own desk in ten minutes, unlike a promise in a privacy policy.
If a vendor cannot answer these in plain language, that is the answer.
For what it is worth, our answers are: on your machine; neither, we never receive one; not applicable; not applicable; nothing to delete; yes, watch the traffic. The Privacy Policy lists everything we do hold.
Because their software runs on their servers. To place an order on your slave account, something has to be logged into it — and if that something is in a data centre you do not control, your credentials have to travel there.
It is not carelessness on their part; it is a direct consequence of hosting the copier for you. Change where the copier runs and the requirement disappears.
Safer than a master password, but "read-only" is not the same as "no risk". An investor password exposes your full position and balance history to whoever holds it.
It also cannot place trades — which is why a cloud copier can only use it on the master account. For the slave accounts, where orders actually get written, it will need the master password.
In your operating system’s native keystore on the machine running the terminal — Windows Credential Manager or the macOS Keychain — encrypted by the OS under your user account.
They are never transmitted to us and we have no copy to hand over, lose, or be compelled to produce. Uninstall R4Copier and they are removed with it.
Watch the traffic. Run the terminal behind any network monitor you like — Wireshark, Fiddler, your firewall’s connection log — and confirm for yourself that the broker login goes to your broker and nowhere else.
That is the practical advantage of a claim about architecture over a claim about policy: you can test it from your own machine in ten minutes.
This is where it matters most. A funded account represents an evaluation you paid for and passed, and its credentials are usually the only thing standing between an attacker and a breach of your firm’s rules.
Most prop firms also treat credential sharing as your responsibility under their terms. Keeping the login on your own machine keeps that responsibility somewhere you can actually discharge it.