FillScope

Security and privacy

How does FillScope handle IBKR Flex and trading data?

FillScope treats trading records and connection settings as account-scoped data and keeps them behind authenticated product routes.

What happens to the Flex token and query ID?

The server needs both values to request an IBKR Flex report. After configuration, the settings API does not return the full Flex token or query ID; it returns configured flags and a masked tail. Application logs redact keys such as token, query ID, account ID, password, and secret.

Are the credentials encrypted at rest?

The public product must not claim a storage control that has not been verified. Verify the deployment's storage and backup controls, access restrictions, retention, and encryption-at-rest requirements before connecting a production account. Revoke or rotate the Flex token in IBKR when access is no longer needed or exposure is suspected.

Which data is public?

Private trades, positions, settings, reviews, and analytics require authentication. Public product and methodology pages contain no account data. A share report is public only through its generated, revocable, expiring URL and is designed to exclude account ID, Flex token, query ID, and raw XML.

How should a Flex query be scoped?

Use a dedicated query with only the fields and history needed for the journal. Do not reuse or publish credentials. Review Interactive Brokers' current Flex documentation and token controls, because broker behavior and permissions are outside FillScope.

What should a user do after suspected exposure?

Disable or rotate the token in Interactive Brokers, clear the saved credential in FillScope, end active sessions where possible, review import and account activity, and contact support. Broker-account security actions must be completed in IBKR.