Security
Institutional security boundaries
Secrets never reach the browser. Provider credentials, wallet material, JWT signing secrets, and Supabase service-role keys stay server-side.
- • Row Level Security on application tables
- • Scoped API keys — no unrestricted defaults
- • Audit logs for login, key lifecycle, wallet connection, trade authorization, Credit overrides
- • Trading disabled until explicit consent + provider authorization + confirmation UI
- • Paid placement never changes Credit