Security & Trust

Your keys never leave your control.

AlgoVesta connects to your exchange with trade-only API keys — encrypted, isolated, and never able to withdraw a single unit of your funds.

Non-custodial AES-256 encryption Trade-only permissions 2FA on live actions

Our core security principles

We never ask for withdrawal access

Every exchange connection uses API keys scoped to trading only. Withdrawal and transfer permissions are never requested, and most exchanges block them by design at the key level.

Your funds stay on your exchange

AlgoVesta never custodies your assets. Your balance, deposits and withdrawals are managed entirely inside your own exchange account — we only send trade instructions.

Keys are encrypted, not stored in the open

API keys and secrets are encrypted at rest with AES-256 before they touch our database. They are decrypted only in memory, only at the moment a trade is executed.

You can revoke access in seconds

Disconnect an exchange or rotate your keys any time from your dashboard, or directly from your exchange account — access ends immediately, on both sides.

How your keys are protected, step by step

1You create a trade-only keyFollowing our exchange-specific setup guide, you generate an API key on your exchange with trading permissions only — no withdrawal, no transfer.
2It's encrypted before it's storedThe key and secret are encrypted with AES-256 the moment they reach our servers. Nothing is ever written to disk in plain text.
3It's used only to place your tradesWhen a signal is approved, the key is decrypted in memory for that single request to your exchange, then discarded — never cached in readable form.
4You stay in controlRotate, revoke or replace your key at any time. Revoking on your exchange instantly cuts off all access, independent of anything on our side.

Platform & account security

Isolated, monitored infrastructure

Signal processing, AI analysis and trade execution run on dedicated infrastructure with continuous error monitoring and rate limiting. Exchange connections reconnect automatically after any drop.

Two-factor confirmation

Live-money actions and key changes can require an additional confirmation step, reducing the risk of unauthorized changes to your account.

Least-privilege internal access

Internal tools that can view account or key metadata are access-controlled and limited to what's needed to operate and support the platform. Authentication uses hashed credentials — we never see your raw password.

What we store — and what we don't

We store what's needed to run your automation: encrypted API credentials, your strategy configuration, and a log of signals and trades for your own history and support. We do not store your exchange password, and we never request withdrawal or transfer permissions.

Read the full Privacy Policy →

Found a security issue?

If you believe you've found a vulnerability in AlgoVesta, please report it privately so we can investigate and fix it before it's disclosed publicly. We take every report seriously.

Report a vulnerability →

Responsible disclosure policy

1
What's in scope algovesta.com and its subdomains, the customer dashboard, and our public API. Out of scope: your own exchange or broker account, the third-party providers listed on our sub-processors page, social engineering of our staff or customers, and denial-of-service or high-volume load testing.
2
Safe harbour If you act in good faith, stay within the scope above, and do not access, modify or copy data belonging to other users, we will not pursue legal action against you for your research. Please give us a reasonable opportunity to fix the issue before disclosing it publicly.
3
What happens after you report We aim to acknowledge every report within 48 hours. We will keep you updated while we investigate, and we will tell you once the issue has been fixed. If you would like to be credited, let us know and we will name you.
4
Rewards We do not currently run a paid bug bounty programme, and we would rather say so plainly than leave you guessing. Reports are still very welcome and we will always credit researchers who ask for it.

Machine-readable contact details: security.txt (RFC 9116)

FAQ

Security FAQ

The most common questions before you decide — if you still have doubts, start here.

Can AlgoVesta withdraw or transfer my funds?

No. API keys are created with trading permissions only. Withdrawal and transfer permissions are never requested and are typically blocked by the exchange itself when the key is created correctly.

What happens if AlgoVesta's systems are ever compromised?

Because keys are encrypted at rest and scoped to trading only, even in a worst-case breach scenario your funds cannot be withdrawn. You can also revoke your key instantly from your exchange account.

Do you ever see my exchange account password?

No. AlgoVesta never asks for your exchange account password — only an API key and secret, which are encrypted before storage.

How do I disconnect AlgoVesta from my exchange?

Remove or deactivate the API key from your dashboard, or delete/deactivate it directly on your exchange — either action immediately ends AlgoVesta's access.

Ready to automate with confidence?

Connect a trade-only API key and keep full custody of your funds, on your own exchange.

Get started →