Security First

Your Assets. Your Keys.Our Protection.

We take security seriously at every layer — from encryption at rest with AES-256, to integrity verification with SHA-256, to API keys with the absolute minimum privileges. Your funds stay safe because we never ask for withdrawal access.

Data Protection

Enterprise-Grade Encryption

AES-256 Encryption

All sensitive data — including your exchange API keys — is encrypted at rest using AES-256, the same standard trusted by governments and financial institutions worldwide.

SHA-256 Integrity

We use SHA-256 cryptographic hashing to verify data integrity at every step. Passwords are salted and hashed — never stored in plain text — ensuring your credentials remain protected even in the unlikely event of a breach.

TLS Encryption in Transit

Every connection between your browser, our servers, and exchange APIs is secured with TLS 1.2+ encryption. Your data is protected in motion, not just at rest.

API Key Policy

Minimal Privilege. Zero Withdrawal Access.

How It Works

Least-Privilege API Keys

When you connect an exchange, we only ask for API keys with the absolute minimum permissions needed to trade. We never request or require withdrawal privileges.

  • Read-only market data — to fetch prices and order books
  • Spot & futures trading — to place and manage orders
  • No withdrawal permission — funds can never leave your exchange
  • No transfer permission — no internal or sub-account transfers

Your Control

You Stay in Command

Your exchange account belongs to you. We never custody your funds, and your API keys can be revoked at any time directly from your exchange dashboard. You are always in full control.

  • Revoke API keys at any time from your exchange
  • IP-whitelist your API keys for an extra layer of protection
  • Non-custodial — your funds never leave your exchange
  • Delete your API keys from our platform at any time

Infrastructure

Built on Trusted Cloud Infrastructure

AWS Infrastructure

Our platform runs on Amazon Web Services, leveraging their SOC 2, ISO 27001, and PCI DSS compliant infrastructure for world-class reliability and security.

Automated Backups

Encrypted automated backups ensure your configurations and trading history are always recoverable. Backups are stored in geographically separate regions for disaster resilience.

Continuous Monitoring

24/7 monitoring and alerting keeps our platform secure. Suspicious activity is detected and mitigated in real time so your bots keep running safely.

Trade with Confidence.

Your security is not an afterthought — it is the foundation everything else is built on. Start trading with a platform that puts your safety first.

Are you a security researcher? We run a Security Bounty Program — report vulnerabilities and earn rewards for actionable findings.