Security & Privacy
Local-first design — your keys stay on your machine, never logged, never uploaded.
Security & Privacy
CoTrading is local-first by design. Your sensitive data stays on your machine, and the architecture is built so the AI can never move your funds.
Your keys stay local
Both your exchange API keys and your AI model keys are:
- Stored on your own machine.
- Never written to logs.
- Never uploaded to any server.
This applies whether you use hosted AI credits or bring your own model key.
Separate slots for live and testnet
Live and testnet exchange keys are kept in separate slots and never mixed, so it is always explicit which environment you are operating in. See Connect an Exchange.
Disable withdrawals
CoTrading validates that your live API key has withdrawal permission disabled before live trading is allowed. Even in a worst case, a trading-only key cannot move funds off the exchange.
The AI cannot place orders
The safety boundary around your capital is structural, not just a setting:
- The AI process has no order authority — it only produces trade plan cards for your review. See AI Approval Trading.
- Deterministic Risk Controls run locally as pure functions and never pass through an LLM.
Local-first, you in control
Your credentials, your data, and every trading decision stay under your control. CoTrading is a tool that assists you; it never takes the wheel on your money. Trading involves risk.
Next steps
- What is CoTrading — the product overview and core principle.
CoTrading Docs