Protect account access, connections and trading activity.
Evolution Zenith security is structured around controlled account access, restricted exchange API permissions, operational event monitoring and clear incident-response actions.
- Account access protection
- Restricted API permissions
- Security event monitoring
- Connection and strategy interruption
Account credentials, devices and exchange-side security settings must also be protected by the user.
Protect every stage between account access and order execution.
A connected trading platform has several security boundaries. Login controls protect the platform account, API restrictions control exchange access, risk validation governs eligible actions and monitoring provides visibility into operational events.
- ✓ Account authentication and session control protect platform access.
- ✓ API permissions define what information and actions may reach the exchange.
- ✓ Monitoring and interruption controls support a structured response to anomalies.
Validates platform access through account credentials and available verification controls.
Tracks active access and allows sessions to be reviewed or terminated.
Restricts connected account access to explicitly enabled API functions.
Checks strategy and risk conditions before an action becomes eligible for routing.
Records important access, API, strategy and operational events for review.
Reduce unnecessary access across every connected account.
Security begins with limiting who can access the platform, which sessions remain active and what connected credentials are permitted to do.
Strong account credentials
Use unique credentials that are not shared with exchange, email or unrelated service accounts.
- Use a unique and sufficiently long password
- Avoid credential reuse across services
- Change access details after suspected exposure
Additional verification
Use an additional validation step where available instead of relying on a password alone.
- Enable two-step verification
- Protect access to the verification device
- Store recovery information securely
Session review
Review active sessions and remove access that is no longer recognised or required.
- Check active account sessions
- Terminate unrecognised access
- Sign out from unused devices
Device protection
Secure the computers and mobile devices used to access the platform and connected exchanges.
- Apply operating-system updates
- Use device-level access protection
- Avoid untrusted extensions and software
Access recovery
Maintain a secure process for restoring account access without exposing recovery details.
- Protect the connected email account
- Keep recovery details outside public devices
- Review account information after recovery
Message verification
Treat unexpected login requests, links and credential prompts as potential phishing attempts.
- Verify the destination before entering credentials
- Do not disclose API secrets through messages
- Report suspicious communication
Manage exchange credentials from creation to revocation.
An API key should remain active only while it serves a defined account connection and retains the correct permissions.
Create a dedicated key
Generate credentials specifically for the Evolution Zenith connection rather than reusing an existing key.
Limit permissions
Enable only the read and trading functions required by the intended platform workflow.
Validate the connection
Confirm that balances and authorised functions respond correctly before strategy activation.
Review ongoing use
Check connection health, permission changes and unexpected exchange or platform activity.
Revoke when unused
Remove the platform connection and revoke the corresponding key directly at the exchange.
Make important account and connection events visible.
Event monitoring helps users distinguish normal platform activity from changes that require additional verification or an immediate operational response.
Security event history
Illustrative platform access and connection records.
Unexpected access or permission changes should be investigated before normal trading resumes.
Sessions and API connections that are no longer required should be removed rather than left active.
Connect security alerts to immediate operational actions.
A structured response should first reduce additional exposure, then investigate the source, restore safe access and review the account before trading continues.
Restrict activity
Stop new automated actions and prevent the event from creating additional account exposure.
- Pause affected strategies
- Review pending orders
- Terminate unfamiliar sessions
Verify the source
Determine whether the issue originated from account access, an API connection, a device or the exchange.
- Review recent platform events
- Inspect exchange activity
- Check connected devices and email access
Replace exposed access
Change or revoke any credentials that may no longer be trusted.
- Change account credentials
- Revoke affected API keys
- Reconfigure verification controls
Restore deliberately
Reconnect accounts and reactivate strategies only after the environment has been reviewed.
- Validate new API permissions
- Review open positions and balances
- Resume trading in controlled stages
Understand which party controls each part of the security model.
Platform security, exchange security and user security overlap, but they do not replace one another.
| Security area | Primary responsibility | Required action | Platform visibility | Important limitation |
|---|---|---|---|---|
| Platform password | User | Create and protect unique credentials | Account authentication | The platform cannot secure an exposed device |
| Exchange API key | Shared | Limit permissions and revoke when unused | Connection and permission status | The exchange defines available controls |
| Exchange account custody | Exchange | Maintain provider-side account protection | Connected account information | Provider custody rules remain independent |
| Strategy permissions | Platform | Validate strategy and risk conditions | Strategy state and activity records | Controls cannot eliminate market risk |
| User device security | User | Protect devices and installed software | Limited session information | Device compromise may expose several accounts |
| Incident investigation | Shared | Review events across all relevant systems | Platform and connection event records | No single system contains every relevant event |
Questions about account, API and trading security.
Review how security controls interact with connected exchange accounts and automated strategies.
Does Evolution Zenith hold cryptocurrency funds?
Should an exchange API key allow withdrawals?
What should I do after seeing unfamiliar account activity?
Can security controls prevent every loss or account incident?
How often should API keys be reviewed?
What happens when an API connection is disconnected?
Build trading access around controlled permissions and visible events.
Protect platform access, exchange API connections and automated activity through a structured security workflow.
Security notice: No online platform, exchange connection or account control can eliminate every security risk. Users remain responsible for protecting credentials, devices, email accounts, exchange settings and recovery information. Interface values shown on this page are illustrative and do not represent a guarantee of security.