Skip to main content

Security & Best Practices

Security and governance

Account security

The system protects user accounts through login-related security mechanisms such as passwords, additional identity verification, and session management, to help reduce the risk of unauthorized account access.

Data security

Data related to your account and platform usage is handled under appropriate security practices to reduce the risk of leaks, unauthorized access, or use beyond what is necessary.

Exchange-connection security

Connecting an exchange account via API key is an important part of using the platform. You should grant only the permissions necessary for the system to work, and review your exchange account's security settings in parallel, to help reduce risk from inappropriate API use.

Internal-operation security

The system may include access controls, operation monitoring, and alerts for important events to help make using the platform's functions more secure and auditable.

User-side configuration and usage security

Even with platform-level security measures, real-world security also depends on your settings — such as using a strong password, enabling 2FA, safeguarding your API key, and regularly reviewing notifications.

Setting a strong password

A password is one of the most important basic mechanisms for protecting your account. A weak, easy-to-guess, or reused password puts your account at high risk of unauthorized access.

Recommended practices

  • Use a password that is long enough and hard to guess. Avoid information directly related to you, such as your name, birthday, phone number, or common words. A good password contains uppercase letters, lowercase letters, numbers, and special characters in appropriate proportions.
  • Do not reuse the same password across multiple systems — especially your email, exchange accounts, or other financial services — because a leak in one system could affect others sharing the same password.
  • Change your password immediately if you suspect your account is at risk, such as unfamiliar activity, abnormal login alerts, or exposure of credentials in an unsafe environment.

Using 2FA correctly

Even though passwords matter, a password alone may not be enough to protect your account if credentials leak. Enabling 2FA adds another layer of identity verification before logging in or performing certain important actions.

Recommended practices

  • Enable 2FA on your Nanobot account and your connected exchange accounts whenever supported, primarily using a trusted authenticator app. If multiple options are available, choose the method whose security fits your account's risk level.
  • Keep your recovery codes in a safe place separate from your main device, for use if you lose your phone, change devices, or cannot access your authenticator app.
  • Before changing phones, resetting the device, or removing the authenticator app, make sure you have transferred or backed up your 2FA access — otherwise you may not be able to log in.

API key best practices

An API key is an important credential directly related to account access and automated actions. Granting excessive permissions or storing the key insecurely can significantly increase risk, so understand the scope of permissions before connecting.

Key principles

  • Create an API key specifically for use with Nanobot, and do not reuse the same key across multiple external systems or services. Separating keys by purpose makes it easier to control risk, track usage, and revoke access if a problem occurs.
  • Grant the API key only the permissions necessary for the system to work — such as reading account data or executing trades that the platform needs — and avoid enabling permissions unrelated to actual use.
  • Review the permission details every time before connecting an API key, and review the settings periodically — especially after changing strategy, changing your plan, or noticing anything unusual.

Nanobot

  1. Enable Reading — Always enable if the platform needs it to read account data, balances, asset status, order history, or related display data.
  2. Enable Spot & Margin Trading — Enable only when you want the system to place trades in the Spot market or use related functions. For Nanobot's mainly Spot-based use, enabling just this part is enough.
  3. Restrict access to trusted IPs only — Enable IP restriction and add only the system's trusted IPs.
  4. Enable Futures — Enable only if the platform supports Futures and you actually intend to use it.
  5. Enable Symbol Whitelist — Consider enabling if the exchange supports it and you want to restrict trading to certain pairs.

Nanobot

Permissions you should NOT enable

  1. Enable WithdrawalsNever enable. Withdrawal is the highest-risk permission. For a typical trading bot there is no normal reason for the API to withdraw assets; if enabled, damage is immediate and severe should the key be misused.
  2. Enable Margin Loan, Repay & Transfer — Do not enable unless there is a specific need. This relates to borrowing, repaying, and transferring within the exchange and greatly expands capital and portfolio risk.
  3. Permits Universal Transfer — Do not enable unless truly necessary. This transfer permission between wallets or sub-accounts increases asset-movement risk and is generally not needed to open/close trades.
  4. Enable Futures — Do not enable if you or the system don't actually use Futures. Although not as dangerous as withdrawal, it unnecessarily expands trading scope and can add leverage risk.
  5. Unrestricted IP Access — Do not choose unrestricted IP if a restricted option exists. Allowing all IPs is not recommended, and granting more than Reading without IP restriction is very high risk.

Nanobot

Privacy and data protection

Nanobot values your privacy and data protection. Data related to using the platform is handled within the scope necessary for service delivery, security, usage support, and improving system quality. Data is protected with measures appropriate to its nature and the related risks, and access is limited to what is necessary for operations.

You should still be careful about storing and using your own sensitive information — such as passwords, verification codes, and API keys — and should review the privacy policy and related documents to understand the details of data handling and your related rights.

Usage limitations

  1. Service-coverage limits. The platform may not support every exchange, pair, market, or function in the same way. Availability of some services can vary by account type, API-key permissions, plan, or third-party requirements.
  2. System-availability limits. The system may be unavailable at times — for maintenance, updates, network issues, or third-party problems — which can affect data display, exchange connectivity, or certain operations.
  3. Data and display limits. Some data within the platform may be delayed, incomplete, or different from the source exchange at times — especially during high volatility, network delays, or external API limits.
  4. Order-execution limits. Placing orders through automation does not mean orders are always executed at the expected price or conditions, because actual results may be affected by liquidity, the current price, connection delays, or exchange limits.
  5. Investment-result limits. The platform is a tool to help execute strategies, not a guarantee of returns. Do not interpret using bots or automation as fully reducing market risk or guaranteeing profit.
  6. Security limits. Although the system has security measures, it cannot guarantee complete protection in every case — especially risks from your own device, inappropriate settings, exposed credentials, or external services beyond the platform's control.

Prohibited uses

  1. No illegal use. Do not use the platform for purposes that violate laws, regulations, or the requirements of relevant authorities — including fraud, money laundering, or other unlawful activity.
  2. No use beyond granted permissions. Do not attempt to access data, systems, accounts, or functions you are not entitled to, and do not try to bypass the platform's access controls.
  3. No disrupting or damaging the system. Do not do anything that could make the system malfunction, slow down, become unstable, or be damaged — such as sending abnormally many requests, attempting attacks, misusing automation tools, or interfering with the platform's mechanisms.
  4. No using others' credentials. Do not use another person's account, password, API key, verification code, or other credentials without clear authorization.
  5. No exposing or misusing API keys. Do not share API keys, secret keys, recovery codes, or other security information through unsafe channels, or store them in ways that risk unauthorized use.
  6. No use beyond supported purposes. Do not use the platform outside its design scope — such as trying to use functions with markets or services the system does not support, or enabling excessive API permissions for uses beyond normal cases.
  7. No relying on the system without proper review. Do not use automation without understanding the settings, strategy, risks, and limits of the functions used. Incorrect or market-mismatched settings can lead to unexpected results.
  8. No false or misleading information. Do not provide false data, falsify account information, or use information that could mislead when registering, using, or connecting external services through the platform.