How we protect your money.

Tengu reads positions and submits orders through the brokerage you already use. Your funds never leave your broker. We hold a read-and-trade permission you can revoke at any time.

Bank-grade security.

AES-256 at rest, TLS 1.3 in transit, encrypted broker credentials.

Bank-grade security.

Never custodial

Tengu is not a broker-dealer. Your funds remain with Robinhood, Schwab, IBKR, Coinbase, or whichever broker you connected. We hold a scoped read-and-trade permission. You can revoke it inside Tengu or from your broker.

Hard risk gates

Every order passes a VaR check, a leverage cap, a position-size limit, and a drawdown circuit breaker before it reaches your broker. The same gates run on our own live capital. No exceptions, no override.

SOC 2 underway

Type II audit in progress with target completion in Q3. AES-256 at rest, TLS 1.3 in transit, KMS-backed secret rotation, GDPR-compliant data handling, and OIDC-only deploys from CI.

How custody actually works.

When you connect a broker to Tengu, the connection is authorized through Plaid or a direct OAuth integration with the broker. Tengu never sees your broker password. We receive a scoped token that lets us read positions and submit the orders you approve.

Your money stays where it always was. Robinhood holds your Robinhood balance. Coinbase holds your crypto. Interactive Brokers holds your IBKR account. Tengu has no ability to move funds out of those accounts to anywhere except where the broker's own policy already allows.

When Tengu submits a trade, it lands inside your broker exactly as if you had clicked Buy on the broker's own app. Fills, settlements, statements, and tax reporting all happen at the broker. We are the brain. The broker is still the bank.

You can revoke Tengu's permission at any time, from inside Tengu or from your broker's own app. When the permission is revoked, our access stops immediately and the connection is purged from our backend within minutes.

Every trade passes these checks first.

The risk engine that runs on our own live capital runs on every subscriber. There is no manual override.

01
Value at Risk

Reject the order if 95% one-day VaR on the resulting portfolio exceeds 2% of net asset value.

02
Leverage cap

Net leverage caps at 2.0x by default. Configurable up to 5.0x with an explicit acknowledgement screen.

03
Position-size limit

No single ticker may exceed 20% of portfolio value post-trade. Resizing happens silently before the order is sent.

04
Drawdown circuit breaker

Automated execution pauses at minus 5% daily, minus 10% weekly, or minus 15% monthly. Resuming requires an explicit click.

05
Manual kill switch

A flag in DynamoDB can pause every automated subscriber within seconds. Used by our on-call team during incidents.

The infrastructure under the brain.

Twenty-two Terraform modules. Multi-AZ across us-east-1. Edge caching and WAF rules scoped per public surface. Secrets rotated on a cadence we can audit. No long-lived AWS keys in CI.

We trade our own capital on this exact stack every market day. Nothing on a subscriber account runs on infrastructure we don't trust with our own.

Cloud
AWS, us-east-1 primary with multi-AZ failover
Infra as code
Terraform, 22 modules, S3-backed remote state, DynamoDB locks
CI / CD
GitHub Actions over OIDC, no long-lived AWS keys
Edge
CloudFront + AWS WAF per hostname, region-aware rules
Secrets
AWS Secrets Manager + KMS rotation, scoped per service
Encryption
AES-256 at rest, TLS 1.3 in transit, HSTS preload
Observability
CloudWatch logs and metrics, structured tracing, alerting
Data residency
United States, with EU expansion planned for 2026

Responsible disclosure.

Found a vulnerability? Email us before you publish. We reply within one business day, fix in cooperation with you, credit you in the changelog, and pay bounties on valid reports.

support@tengu.co

Built like we mean it.

Tengu trades our own capital on the same risk engine, the same broker connections, and the same infrastructure that runs every subscriber.

Contact security