Security

Your keys stay yours.
So does your money.

The claim that matters isn't a checkbox — it's structural. Stralines cannot move funds out of your account, because it never holds the permission to.

Built so a breach can't cost you money

Never holds your funds

Trading runs on your own exchange API keys. Withdrawal permission is never requested or granted — a structural property of the system, not a promise.

Read + trade scope only

The key Stralines asks for reads account state and places or cancels orders. Paste a withdrawal-scoped key and the platform refuses to save it.

Keys encrypted at rest

Even if the database were compromised, keys cannot be read without the application's encryption secret — held outside the database, separately scoped and rotated.

Privileged routes gated at the edge

Admin and operator surfaces are protected at the network edge before traffic reaches the platform. Public and operator surfaces are separated end to end.

31,000+
automated tests per release
1,600+
test suites
13
stage release pipeline
₹0
customer funds held

Internal security review runs continuously as part of the engineering operating model. External quarterly review is on the roadmap as the platform scales.

The questions traders
actually ask.

Orders already placed continue to live on the exchange — your stop-loss and take-profit sit there, not on Stralines. The three-layer self-heal recovers orders the exchange itself drops; if Stralines is unreachable, your protection still lives on the venue.

Read and trade only. Withdrawal scope is never requested. Most exchanges enforce this at key creation, and we additionally reject withdrawal-scoped keys at the point of saving.

Keys are encrypted at rest with an application secret held outside the database. Operator surfaces do not expose decrypted key material, and access is logged.

Production data sits within the Stralines infrastructure footprint, geo-located primarily in the regions our customers operate from. Data-at-rest encryption is on by default at the storage layer.

Email security@stralines.com with a description and a reproduction path. Acknowledgement within 1 business day, initial assessment within 5.

Responsible disclosure

Found something?

Email security@stralines.com with a description and a reproduction path. Acknowledgement within 1 business day, initial assessment within 5.