Our commitments
- No exchange API keys collected
- Passwords hashed (bcrypt)
- Server-side role checks on admin APIs
- Rate limiting and secure HTTP headers
- Generic password-reset responses (no token in production API)
Email security@tesbot369.com with a clear description and proof-of-concept. Do not access other users’ data. We will acknowledge reports and prioritise critical issues.