Account & API-Key Safety
Use API keys scoped to trading + read only — never enable withdrawals. Keys are stored encrypted. Rotate keys if you suspect exposure. The platform never displays your secret key after entry.
Enable two-factor authentication on your exchange and on your BiTi account.
- API-key scoping: trading + read only, withdrawal permission disabled.
- Encrypted key storage; secret is never re-displayed after entry.
- Two-factor authentication on the exchange and on the BiTi account.
- Network isolation: admin/actuator surfaces are access-controlled and are not exposed unauthenticated.
- Role-based access control (RBAC): control actions are role-gated; monitor surfaces are read-only.
- Audit logging: trading toggles and control actions are recorded.