Security

Our commitments

  • No exchange API keys collected
  • Passwords hashed (bcrypt)
  • Server-side role checks on admin APIs
  • Rate limiting and secure HTTP headers
  • Generic password-reset responses (no token in production API)

Responsible disclosure

Email security@tesbot369.com with a clear description and proof-of-concept. Do not access other users’ data. We will acknowledge reports and prioritise critical issues.