Last updated: August 18, 2026
1. Key storage
If a User adds API keys or secrets for connecting to an exchange, wallet, or other service, AI Traders encrypts them using AES-256-GCM before storage. Keys are stored separately from account information and accessed only when needed to fulfill a User request.
AI Traders has no mechanism to decrypt and view stored keys. If a User loses access or forgets where they stored a key, they must remove the integration and add a new key.
2. Permissions and fund access
AI Traders does not request withdrawal permission (withdrawal access) for any feature. If an integration does not require the ability to withdraw funds, the User must explicitly disable this permission on the exchange or wallet.
The User bears full responsibility for granting and revoking permissions. AI Traders recommends using the minimum necessary permissions and applying IP restrictions where possible.
3. Two-factor authentication (2FA)
In the current version, two-factor authentication for account sign-in is not enabled. This is planned for future versions. Users should choose strong passwords and protect their browsers and devices.
For services integrated with AI Traders (e.g., exchange accounts), the User should enable two-factor authentication on those services themselves.
4. Monitoring and audit
AI Traders logs important events, such as sign-ins, configuration changes, key additions, and errors. Logs are used to detect suspicious activity, diagnose incidents, and improve security.
5. Reporting vulnerabilities
If you discover a security vulnerability, please report it to security@aitraders.online. Provide details but do not publicly disclose the vulnerability until it is fixed. Thank you for helping to keep the platform secure.