Security

Your money stays in your own account. Always.

Yielox runs no wallet and holds none of your funds. The bot can only place buy and sell orders. This page says exactly what we can do, and what we never can.

Access boundary

What we can do, and what we never can

The key you create decides what the bot can reach. We ask for the least access the bot needs.

The bot can

  • Read your wallet balances on the exchange.
  • See your open orders and past fills.
  • Place buy and sell orders for the grid strategy.
  • Cancel its own orders.

The bot can never

  • Withdraw from your account.
  • Transfer funds to another account or wallet.
  • See or know your exchange password.
  • Take a percentage of your profit.
Key protection

How your API key is stored

Your key can only place orders, but we still treat it like a password: encrypted, kept apart and never shown again.

Envelope encryption with AES-256-GCM

Each key is encrypted with its own data key, and that data key is wrapped by a ring of master keys.

Bound to your account

The encryption is tied to your account ID. An encrypted key from one account cannot be used for another.

Write-only

Once saved, the key is never shown again, not to you and not to anyone else. You can only replace or remove it.

Decrypted only to trade

The key is decrypted only inside the trading process. No page or report ever returns it in plain text.

Isolated in the database

Postgres row-level security keeps each account's data apart, a second layer of protection on top of the application's own checks.

Servers in Iran

Nobitex only accepts requests from an Iranian IP, so the bot runs on servers inside Iran.

Your account

Your Yielox account is protected too

Security is not only about the exchange key. Signing in to the panel, and everything you do there, is protected as well.

Passwords hashed with argon2id

Your password is never stored as is. We keep only its argon2id hash.

Revocable sessions

Sessions are stored only as hashes. See your active sessions in your profile and sign out everywhere with one click.

Security audit log

Sensitive actions such as sign-ins, password changes and key updates are logged, and you can see the log in your profile.

HTTPS, HSTS and a strict CSP

Every connection is encrypted, browsers are told to always use HTTPS, and only the site's own scripts may run.

Risk controls

Brakes built into the bot

Security also means limiting losses. These tools do not remove risk, but they help keep losses within the limits you set.

Per-pair stop-loss

When a pair's loss passes its limit, the bot stops buying or sells the inventory, as you configured.

Trailing stop

Optionally, the stop moves up with profit so part of the gain is kept.

Daily loss halt

If a pair's loss for the day passes its limit, that pair pauses until the next day.

Kill switch

One switch cancels every open order and stops the bot from placing new ones.

You stay in control

Stop it whenever you want

You do not need our permission or a support ticket. The control is fully yours.

  1. Revoke the key on the exchange

    Delete the key on Nobitex. From that moment the bot can no longer trade.

  2. Kill switch

    Turn on the kill switch on the Accounts page to cancel every order.

  3. Pause

    Pause one pair or the whole account, and start it again whenever you like.

Found a security issue?

If you find a vulnerability or anything suspicious, please email the details to support before sharing them publicly. We take every report seriously and will tell you what we found.

support@yielox.ir

Create a safe key in a few minutes

Our step-by-step guide shows how to create a key with read and trade permission only.