Security

Platform Security

Protect account access, connections and trading activity.

Evolution Zenith security is structured around controlled account access, restricted exchange API permissions, operational event monitoring and clear incident-response actions.

  • Account access protection
  • Restricted API permissions
  • Security event monitoring
  • Connection and strategy interruption
Security control centre
Controls active
Account state Protected
Active sessions 01
Connected APIs 01
Open alerts 00
Security control status Illustrative overview
Security layer active
Account access Controlled
API permissions Restricted
Activity monitoring Enabled
Emergency response Available
Access controls Active
2FA
Two-step verification Additional login validation
On
SES
Session review Active access monitoring
On
API
API restrictions Withdrawal access disabled
On
Recent events Normal
Session verified Recognised account access
Now
API connection checked Permissions remain valid
Current
Security review No unresolved alert
Clear
!
User action remains essential

Account credentials, devices and exchange-side security settings must also be protected by the user.

Illustrative security interface. Available controls may depend on account configuration.
Controlled access Verify the identity and legitimacy of account sessions.
Minimum permissions Enable only the exchange API access required for platform use.
Event visibility Record important access, connection and strategy events.
Operational response Connect alerts to account, API and automation controls.
Shared responsibility Platform protection complements user and exchange security.
Security architecture

Protect every stage between account access and order execution.

A connected trading platform has several security boundaries. Login controls protect the platform account, API restrictions control exchange access, risk validation governs eligible actions and monitoring provides visibility into operational events.

  • Account authentication and session control protect platform access.
  • API permissions define what information and actions may reach the exchange.
  • Monitoring and interruption controls support a structured response to anomalies.
Connected security layers Operational boundaries
ACC
Account authentication

Validates platform access through account credentials and available verification controls.

Access
SES
Session management

Tracks active access and allows sessions to be reviewed or terminated.

Session
API
Exchange permission boundary

Restricts connected account access to explicitly enabled API functions.

Connection
RSK
Trading validation

Checks strategy and risk conditions before an action becomes eligible for routing.

Execution
MON
Security event monitoring

Records important access, API, strategy and operational events for review.

Monitoring
Account protection

Reduce unnecessary access across every connected account.

Security begins with limiting who can access the platform, which sessions remain active and what connected credentials are permitted to do.

01

Strong account credentials

Use unique credentials that are not shared with exchange, email or unrelated service accounts.

  • Use a unique and sufficiently long password
  • Avoid credential reuse across services
  • Change access details after suspected exposure
02

Additional verification

Use an additional validation step where available instead of relying on a password alone.

  • Enable two-step verification
  • Protect access to the verification device
  • Store recovery information securely
03

Session review

Review active sessions and remove access that is no longer recognised or required.

  • Check active account sessions
  • Terminate unrecognised access
  • Sign out from unused devices
04

Device protection

Secure the computers and mobile devices used to access the platform and connected exchanges.

  • Apply operating-system updates
  • Use device-level access protection
  • Avoid untrusted extensions and software
05

Access recovery

Maintain a secure process for restoring account access without exposing recovery details.

  • Protect the connected email account
  • Keep recovery details outside public devices
  • Review account information after recovery
06

Message verification

Treat unexpected login requests, links and credential prompts as potential phishing attempts.

  • Verify the destination before entering credentials
  • Do not disclose API secrets through messages
  • Report suspicious communication
API key lifecycle

Manage exchange credentials from creation to revocation.

An API key should remain active only while it serves a defined account connection and retains the correct permissions.

Create a dedicated key

Generate credentials specifically for the Evolution Zenith connection rather than reusing an existing key.

Limit permissions

Enable only the read and trading functions required by the intended platform workflow.

Validate the connection

Confirm that balances and authorised functions respond correctly before strategy activation.

Review ongoing use

Check connection health, permission changes and unexpected exchange or platform activity.

Revoke when unused

Remove the platform connection and revoke the corresponding key directly at the exchange.

Security monitoring

Make important account and connection events visible.

Event monitoring helps users distinguish normal platform activity from changes that require additional verification or an immediate operational response.

Security event history

Illustrative platform access and connection records.

Monitoring active
Event Source Status Action
Account session started Platform Verified Recorded
API permission checked Exchange Valid Continue
Unusual login condition Platform Review Verify access
Invalid API authentication Exchange Blocked Reconnect key
Active sessions 01
Connected API keys 01
Unresolved events 00
Monitored categories Active
Account access events Enabled
Session changes Enabled
API connection events Enabled
Strategy interruptions Enabled
?
Verify unfamiliar activity

Unexpected access or permission changes should be investigated before normal trading resumes.

×
Stop unnecessary access

Sessions and API connections that are no longer required should be removed rather than left active.

Incident response

Connect security alerts to immediate operational actions.

A structured response should first reduce additional exposure, then investigate the source, restore safe access and review the account before trading continues.

Step 01

Restrict activity

Stop new automated actions and prevent the event from creating additional account exposure.

  • Pause affected strategies
  • Review pending orders
  • Terminate unfamiliar sessions
Step 02

Verify the source

Determine whether the issue originated from account access, an API connection, a device or the exchange.

  • Review recent platform events
  • Inspect exchange activity
  • Check connected devices and email access
Step 03

Replace exposed access

Change or revoke any credentials that may no longer be trusted.

  • Change account credentials
  • Revoke affected API keys
  • Reconfigure verification controls
Step 04

Restore deliberately

Reconnect accounts and reactivate strategies only after the environment has been reviewed.

  • Validate new API permissions
  • Review open positions and balances
  • Resume trading in controlled stages
Security responsibilities

Understand which party controls each part of the security model.

Platform security, exchange security and user security overlap, but they do not replace one another.

Security area Primary responsibility Required action Platform visibility Important limitation
Platform password User Create and protect unique credentials Account authentication The platform cannot secure an exposed device
Exchange API key Shared Limit permissions and revoke when unused Connection and permission status The exchange defines available controls
Exchange account custody Exchange Maintain provider-side account protection Connected account information Provider custody rules remain independent
Strategy permissions Platform Validate strategy and risk conditions Strategy state and activity records Controls cannot eliminate market risk
User device security User Protect devices and installed software Limited session information Device compromise may expose several accounts
Incident investigation Shared Review events across all relevant systems Platform and connection event records No single system contains every relevant event
Security FAQ

Questions about account, API and trading security.

Review how security controls interact with connected exchange accounts and automated strategies.

Does Evolution Zenith hold cryptocurrency funds?
Under the intended exchange-integration model, connected assets remain associated with the user’s exchange account. The exchange provider’s custody and account rules continue to apply.
Should an exchange API key allow withdrawals?
Withdrawal access is not required for ordinary portfolio monitoring, order routing or automated trading. It should remain disabled where the exchange supports separate permissions.
What should I do after seeing unfamiliar account activity?
Pause affected automation, terminate unfamiliar sessions, review platform and exchange events, change exposed credentials and revoke any API key that may no longer be trusted.
Can security controls prevent every loss or account incident?
No. Security controls reduce certain operational risks but cannot eliminate phishing, device compromise, exchange failures, market losses, user error or every possible technical event.
How often should API keys be reviewed?
API keys should be reviewed whenever permissions, exchange accounts, trading requirements or connected devices change. Unused keys should be revoked rather than retained indefinitely.
What happens when an API connection is disconnected?
The platform should stop receiving data and routing new actions through that connection. The corresponding key should also be revoked directly at the exchange to complete the removal.
Evolution Zenith Security

Build trading access around controlled permissions and visible events.

Protect platform access, exchange API connections and automated activity through a structured security workflow.

Security notice: No online platform, exchange connection or account control can eliminate every security risk. Users remain responsible for protecting credentials, devices, email accounts, exchange settings and recovery information. Interface values shown on this page are illustrative and do not represent a guarantee of security.