Security

Your funds always stay in your own hands

The biggest fatal flaw of automated trading SaaS is the single point of failure from centrally custodied API keys. This page explains how TVSBot is designed to avoid that risk, and how you can verify it.

🔓
Non-custodial
The platform never holds your money. Funds always stay in your exchange account; we can only send signals and place orders.
🔐
Fernet encryption
Your API key is stored encrypted with AES-128-CBC. The master key lives in Fly secrets — even our database can't read the plaintext.
🛑
Withdraw permission checked at binding
When you add a Binance, OKX or Bitget key, we ask the exchange for its permissions and refuse keys with Withdraw enabled. Bybit, BingX and Gate.io can't be checked automatically yet, so please verify it yourself.

Why we wrote this page

In December 2022, the largest crypto auto-trading brand 3Commas suffered the worst API key leak in history. At the time they custodied over 1 million exchange API keys; around 100,000 were leaked. On-chain analyst ZachXBT verified $14.8M in losses across 44 victims, with total theft estimated at around $22M. The CEO initially denied responsibility, then publicly admitted it and asked Binance / OKX / KuCoin to revoke keys — because the keys belonged to other platforms, 3Commas couldn't fix it unilaterally.

The incident exposed a structural problem: once a custodial bot platform's single database is breached, every user's funds are exposed at once. TVSBot was designed from day one to avoid this failure mode.

What our architecture looks like

1. Fernet AES-128-CBC encrypted storage

Your API key and secret are wrapped with Fernet symmetric encryption the moment they enter the database. Fernet is the AEAD scheme provided by the Python cryptography library (AES-128-CBC + HMAC-SHA256), widely used across the industry.

The encryption key FERNET_MASTER_KEY lives in Fly secrets — **never committed to git, never in DB backups, never written to any log**.

GitHub open-source PoC (partial): app/services/crypto.py is available for audit.

2. Withdraw permission checked at binding

When you add a key, we call the exchange's permission API (Binance, OKX, Bitget). A key with Withdraw permission is rejected; if the check fails, the key is not accepted either and you'll be asked to retry. Bybit, BingX and Gate.io can't be queried automatically yet, so please verify it yourself. Keys you added earlier are re-checked whenever you press "Check", and a warning appears on the API Keys page if Withdraw is enabled.

As long as a key has no Withdraw permission, even a stolen key can't move your funds off the exchange — the attacker can only place trades. The worst case is a wash trade losing a small amount of fees.

3. IP allowlists: we have no fixed IP today, so please don't enable one

Every exchange API supports IP allowlists, and in theory that's a great extra layer. Honestly though: TVSBot's backend runs on Fly.io's shared egress and has no fixed outbound IP, so there is no address we can give you to put in an allowlist — adding one would just get your orders rejected. Until we buy a dedicated egress IP, please leave allowlists off and reduce risk with "Trade permission only, no withdrawals, key on a sub-account" instead. Once we have a fixed IP we'll show it right on the API Keys page.

4. Signals don't rely on a secret URL

Each user's webhook URL carries a unique token, and the payload includes an additional secret for dual verification. Leaking one can't bypass the other.

Our transparency commitments

  • Incident disclosure: any security incident is publicly disclosed within 72 hours, including scope of impact, technical cause, and remediation status.
  • Encryption implementation public: we don't rely on security through obscurity. Encryption algorithm, key derivation, and storage method are all listed on this page.
  • Third-party audit (planned): first external security audit scheduled for Q3 2026.
  • Bug bounty (planned): see the dedicated section below.

Bug bounty program

We welcome ethical security researchers to report vulnerabilities. We pay reasonable rewards.

In scope

  • tvsbot.com and subdomains
  • Backend API (api.tvsbot.com)
  • Webhook endpoints (replay / spoofing protection)
  • API key encrypted storage and decryption paths
  • Privilege escalation / IDOR / SQLi / XSS

Out of scope

  • DDoS / volumetric attacks
  • Pure social engineering
  • Third-party services (Stripe / Supabase / Fly) — report directly to that vendor
  • Known issues / prior disclosures

Reward tiers (USD, by severity)

Critical (arbitrary user fund loss)$500 – $2000
High (API key leak / privilege escalation)$200 – $500
Medium (IDOR / boundary bypass)$50 – $200
Low (information disclosure / misconfiguration)Hall of fame mention

How to report

Both methods reach us. We commit to an initial response within 48 hours.

Method 2: pre-fill an email with a form

Fill in the form and we'll build a structured email for you, then open your email app so you can press send.

⚠️ Do not exploit vulnerabilities in ways that affect other users. The first researcher to report a finding gets priority reward. Bounties are paid in USDT TRC20 or PayPal.

Comparison with custodial platforms

AspectTVSBot (non-custodial)Custodial bot
Fund custodyYour exchange accountHeld by the platform
Consequence of DB breachAttacker can't decrypt keys + keys with Withdraw are refused at binding1 million keys exposed at once (3Commas 2022)
Withdrawal riskKeys with Withdraw are refused at binding (verify Bybit / BingX / Gate.io yourself)If Withdraw permission exists, funds drained in one on-chain tx
Platform exit-scam riskJust reset your API key and you're doneFunds can't be recovered
Encryption transparencyAlgorithm / key derivation publicMost don't disclose implementation

Further reading