Security is the default, not a feature.

TradeY is built so the platform never has to be trusted with your keys, your capital, or your strategy code. Here's how, layer by layer. In Beta 0 the first layer is the simplest: the build cannot place a real order.

API keys never leave your machine

Beta 0 never asks for exchange keys: it paper-trades on public market data. When live trading returns, this is how keys will be handled — sealed at rest and never transmitted to TradeY infrastructure.

Encrypted at rest

Exchange credentials are sealed with an Argon2id-derived key and AES-256-GCM. OWASP 2024 high-security parameters (m=64 MiB, t=3, p=4).

Passphrase never persisted

The passphrase will decrypt the keystore in memory only. It is never written to disk and must be re-entered whenever the CLI needs a key.

Withdraw scopes rejected

Key storage refuses any key whose advertised permissions include withdrawal, and live runs (not available in Beta 0) check Binance keys with the exchange before the first candle — a key that can withdraw stops the run.

Create keys with read + trade only

The automatic check refuses withdrawal permission; it does not refuse every other scope. When you create a key for a later version, enable read and trade only — no withdrawal, no transfer, no margin — and restrict it to your IP address. How to set it up.

Setting up an exchange API key — for when live trading returns

Beta 0 never asks for exchange keys: paper trading runs on public market data. This is how to create one safely once a later version supports live trading.

  1. Use a dedicated key for TradeY, ideally on a sub-account that holds only money you are prepared to lose. One key per tool, so you can revoke one without touching the others.
  2. Read + trade only. Enable reading and spot trading. Never enable withdrawals, internal or universal transfers. Leave margin and futures off unless your strategy needs them.
  3. Restrict the key to your IP address. On Binance this is "Restrict access to trusted IPs only"; on Bybit, "IP restriction". TradeY runs on your own computer, so allow-list that computer's public IP. A key locked to your IP is useless to anyone who copies it. If your IP changes, update the list — do not switch to "unrestricted".
  4. Store it only in the TradeY CLI (tradey keys add, available again once live trading returns), where it is encrypted with a passphrase only you know. Never paste a key into a chat, an email, an issue or a bot file. TradeY will never ask you for a key, a secret or a passphrase.
  5. Clean up. Delete keys you no longer use, on the exchange and with tradey keys remove.

What TradeY checks for you: the CLI refuses to store a key you declare with withdrawal permission, and a live run on Binance asks the exchange whether the key can withdraw and stops if it can. What it does not check: the IP restriction, and every other scope — those are on you.

One bot, one process, one journal

Each running bot is contained, and every simulated order is journaled.

One OS process per bot

Each tradey run is its own process with its own memory and its own journal. A crash in one bot does not touch any other bot or the host.

Client-order-id idempotency

Every order intent carries a unique UUIDv7 client-order-id, so a retried submission is recognisable as the same order rather than a new one.

Log before submit

Every order intent is written to an append-only JSONL journal before it is filled or sent. Automatic crash recovery from the journal is not built yet: read it with tradey logs to see exactly what a run did.

No live trading in Beta 0

tradey run --dry-run paper-trades on live market prices with simulated fills, and in Beta 0 that is the only mode: live trading is switched off when the app is built, so a bot pointed at a real exchange stops before placing anything, whatever flags you pass.

What TradeY cannot protect against

Honest disclosure. These risks are real and the platform does not eliminate them.

Market risk

Strategies can and do lose capital. Past performance does not predict future returns. A Risk Score is a description of historical behaviour, not a guarantee.

Exchange risk

Beta 0 never trades real funds. Once live trading exists, your funds will sit at the exchange while a bot trades: counterparty risk lives with the exchange, not with TradeY, and if the exchange fails or freezes withdrawals, TradeY cannot recover your balance.

No vaults, no contracts

TradeY runs no vaults and holds no deposits, and Beta 0 uses no smart contracts. Any future on-chain component would carry its own risks and would need an independent audit before use.

User error

Losing your passphrase means losing access to your encrypted keys. TradeY cannot recover them — the encryption is the point. Back up the passphrase out-of-band.

Self-custody, by design.

Read the CLI reference for the operational details, or download the desktop and start authoring.