🔒

Bank-Level Security

Your keys, your funds. We never have access.

Our Security Promise

We use a "Blind Administration" architecture where even platform administrators cannot access your API keys. Your credentials are encrypted with AWS KMS, and only automated Lambda functions can decrypt them for trade execution.

💰

Zero-Custody Architecture

We never hold your funds. All trades execute directly through your exchange account using your API keys.

✓ What this means:
• Your crypto stays in your exchange account
• We can't withdraw or transfer your funds
• You maintain full control at all times
🔐

Blind Administration

Even our system administrators cannot decrypt your API keys. Access is explicitly denied via AWS IAM policies.

✓ How it works:
• Keys encrypted with AWS KMS
• Admins denied decryption permissions
• Only Lambda functions can use keys
🛡️

Military-Grade Encryption

Your API keys are encrypted using AWS Key Management Service (KMS) with AES-256 encryption.

✓ Technical details:
• AES-256 encryption standard
• Customer Managed Keys (CMK)
• FIPS 140-2 validated hardware
📊

Complete Audit Trail

Every single trade execution is logged and visible in your execution history with full details.

✓ You can see:
• Exact time of each trade
• Amount purchased and price
• Order IDs for verification

What We Never Do

Request withdrawal permissions
We only need view + trade access
Store unencrypted keys
All keys encrypted with AWS KMS
See your portfolio balance
We only execute your configured trades
Share or sell your data
Your information stays private

🏗️ Technical Architecture

1. Key Storage

API keys encrypted with AWS KMS (Customer Managed Key) and stored in AWS Secrets Manager

2. Access Control

IAM policies explicitly deny administrators kms:Decrypt permissions

3. Execution

Only authorized Lambda functions can decrypt keys for trade execution

4. Logging

All trades logged to DynamoDB ExecutionHistory table with CloudWatch monitoring

KMS Key ID: cd447309-b069-4dc2-9ae1-00c673987280
Region: us-east-2 (Ohio)
Encryption: AES-256-GCM

You're Always in Control

Revoke access anytime by deleting your API keys from the exchange
Monitor all trades in real-time via execution history
Pause bots instantly by toggling them off in the dashboard
Verify every order on your exchange's order history
Get Started Securely →