Help Center › Security
How AlgoVesta protects your API keys
You never give AlgoVesta your money — only a permission to place trades on your own exchange account.
- AES-256 encryption at rest. Keys are never stored or logged in plain text. Even with database access, they cannot be read.
- Trade-only permissions. During setup you only grant read + trade. The withdrawal permission category is never selected — so withdrawing funds via the API is technically impossible, not just against policy.
- Funds stay on your exchange. AlgoVesta has no custody. Your balance never leaves your own account.
- Instant revocation. Delete the key on your exchange at any moment — AlgoVesta loses access within seconds.
⚠️
If an exchange offers IP whitelisting you may enable it for extra protection — our server IPs are published at launch in the dashboard.
Next: see revoking & rotating keys.