Website requests
The single contact form stores the name, email address, organization, request type, and message you submit. Abuse-prevention fingerprints are one-way hashed before storage.
Member identity
Pegasus uses a private, native account system. Passwords are protected with per-account salts and computationally expensive one-way hashing; plaintext passwords are never stored. Secure session identifiers are stored only in HTTP-only cookies and can be revoked by the owner.
Desktop licensing
License validation receives a serial, a one-way device identifier, application version, device label, and request nonce. The desktop does not send brokerage credentials, account identifiers, positions, orders, provider keys, or trading history to the license authority.
Broker and provider credentials
Desktop credentials remain in Windows-protected local storage. They are not transmitted to this website.