Envelope encryption with AES-256-GCM
Each key is encrypted with its own data key, and that data key is wrapped by a ring of master keys.
Yielox runs no wallet and holds none of your funds. The bot can only place buy and sell orders. This page says exactly what we can do, and what we never can.
The key you create decides what the bot can reach. We ask for the least access the bot needs.
Your key can only place orders, but we still treat it like a password: encrypted, kept apart and never shown again.
Each key is encrypted with its own data key, and that data key is wrapped by a ring of master keys.
The encryption is tied to your account ID. An encrypted key from one account cannot be used for another.
Once saved, the key is never shown again, not to you and not to anyone else. You can only replace or remove it.
The key is decrypted only inside the trading process. No page or report ever returns it in plain text.
Postgres row-level security keeps each account's data apart, a second layer of protection on top of the application's own checks.
Nobitex only accepts requests from an Iranian IP, so the bot runs on servers inside Iran.
Security is not only about the exchange key. Signing in to the panel, and everything you do there, is protected as well.
Your password is never stored as is. We keep only its argon2id hash.
Sessions are stored only as hashes. See your active sessions in your profile and sign out everywhere with one click.
Sensitive actions such as sign-ins, password changes and key updates are logged, and you can see the log in your profile.
Every connection is encrypted, browsers are told to always use HTTPS, and only the site's own scripts may run.
Security also means limiting losses. These tools do not remove risk, but they help keep losses within the limits you set.
When a pair's loss passes its limit, the bot stops buying or sells the inventory, as you configured.
Optionally, the stop moves up with profit so part of the gain is kept.
If a pair's loss for the day passes its limit, that pair pauses until the next day.
One switch cancels every open order and stops the bot from placing new ones.
You do not need our permission or a support ticket. The control is fully yours.
Delete the key on Nobitex. From that moment the bot can no longer trade.
Turn on the kill switch on the Accounts page to cancel every order.
Pause one pair or the whole account, and start it again whenever you like.
If you find a vulnerability or anything suspicious, please email the details to support before sharing them publicly. We take every report seriously and will tell you what we found.
support@yielox.irOur step-by-step guide shows how to create a key with read and trade permission only.