Ballast 0.4.5-beta · Windows · invited beta

Your rules. Your trades. Automated.All guidesDashboard & workflowsTry the bot free

Ballast 0.4.5-beta — full update report

1. Referral counts are rendered as validated numbers through text-only DOM nodes.

Referral counts are rendered as validated numbers through text-only DOM nodes. Hostile remote or cached values cannot become dashboard HTML; the published 0.4.4 issue was reproduced and the corrected renderer was tested in a browser.

2. The launcher now verifies a port-bound server challenge before requesting a 30-second, one-use browser ticket.

The launcher now verifies a port-bound server challenge before requesting a 30-second, one-use browser ticket. The reusable DPAPI access key never travels over HTTP or enters browser URLs. The former key is retired; reopen Ballast from its launcher once after updating.

3. Paper and live trading settings, equity and crypto lists, reserves and runtime state are separated.

Paper and live trading settings, equity and crypto lists, reserves and runtime state are separated. Existing shared settings are copied into both profiles once; existing balances, orders and live parameters are preserved. Stale browser saves are rejected.

4. New paper accounts start with $10,000 simulated cash.

New paper accounts start with $10,000 simulated cash. Existing paper balances stay unchanged; resetting an account remains an explicit action.

5. Optional background paper trading can run alongside LIVE.

Optional background paper trading can run alongside LIVE. Paper Trading has its own settings editor, asset lists and core targets. Live cycles take priority; unfinished, failed or stale paper cycles are discarded. This feature starts disabled.

6. Background paper uses public quotes and simulated fills, skips paid AI news checks, and never promotes settings to live.

Background paper uses public quotes and simulated fills, skips paid AI news checks, and never promotes settings to live. Provider delays, fills and fees can differ from real trading. Missing data can prevent a simulation.

7. Core assets and purchase-only target weights are editable directly in System and Finance using the same draft.

Core assets and purchase-only target weights are editable directly in System and Finance using the same draft. Existing allocation choices remain unchanged.

8. Less-used data sources, trade judgment history, news keys, API guide, past trades, research track record and covered-call sections start collapsed where appropriate..

Less-used data sources, trade judgment history, news keys, API guide, past trades, research track record and covered-call sections start collapsed where appropriate.

9. Tutorial notes stay beside the dashboard, or below it on small screens.

Tutorial notes stay beside the dashboard, or below it on small screens. Lessons open and highlight related sections, expanding collapsed sections as needed. Progress remains explicit and revision-aware.

10. The website now explains novice core-bot practice, daily News and review, and optional advanced Strategies, Ideas, Cloner and specialist research.

The website now explains novice core-bot practice, daily News and review, and optional advanced Strategies, Ideas, Cloner and specialist research. Updated guides, full release history and security-review evidence accompany this release.

Installation and review

Use the app update prompt or System update action. Updates patch program files and preserve private settings, credentials, balances and ledgers. Local trading checks pause during restart. The new local-access key intentionally invalidates old browser sessions: reopen Start Ballast once. The old protected key is retained for rollback and not used by this version. Subsequent updates retain the new session key.

Background paper is opt-in. On Paper Trading, load and review the independent configuration before enabling it while LIVE remains selected. System still edits the selected active mode; account connections and credentials remain application-wide. No paper strategy is automatically copied to live. Existing paper cash is not reset to $10,000.

Verification and limits

Synthetic tests cover mode migration, stale settings, atomic paper publication, real worker lifecycle, live priority, order-route guards, launcher proof and ticket replay/expiry, and hostile referral rendering. The published referral payload reproduced before the fix and did not execute afterward in isolated Chrome. Tests use synthetic data and do not place broker orders. See the signed companion for final test totals and dependency evidence.

The paper worker uses separate staged storage and below-normal process priority. It still shares the computer and briefly publishes to the local database; priority is not a hard real-time guarantee. It may skip cycles, time out or lack prices. Public quotes and simulated fills do not reproduce live execution or AI judgment.

The independent clean-device review and Windows publisher signing remain open. Passing checks are not safety certification or a promise of AI/antivirus approval. A local attacker running as the same Windows user can access that user's protected data. The Cloudflare homepage warning remains under external appeal; this application release does not resolve it. Do not bypass security warnings.

After this release, development is paused pending feedback from multiple beta testers. Review the new controls and report the app version, expected behavior and observed result without sharing credentials or account identifiers.