Data & API Key Storage
How Crypto Pulse protects exchange credentials and what happens when a member disconnects an exchange.
What is stored
For an enabled exchange connection, Crypto Pulse stores the exchange name, connection label, status, permission metadata and encrypted API credential material. We do not request or store an exchange password, 2FA code, seed phrase or wallet private key.
Encryption at rest
The API key, secret and required passphrase are encrypted by the application before they are written to the database. The master encryption key is held separately from the database with restricted operating-system access. Database backups contain encrypted credential material, not plaintext keys.
Use in memory
A credential is decrypted only inside the restricted service process when it is needed for connection verification, an order preview that requires account data or a trade explicitly confirmed by the member. Plaintext credentials are never returned by the portal API or shown again in the client interface.
Where credentials are sent
Credentials are sent only to the API of the exchange selected by the member over an encrypted HTTPS connection. They are not provided to OpenAI, Telegram, NOWPayments, content systems, analytics services or advertisers.
Required exchange permissions
Use a separate trade-only API key. Enable only the read and futures-trading permissions required by the product. Withdrawals and asset transfers must remain disabled. Apply the server IP allowlist shown in the setup guide whenever the exchange supports it.
Logs and browser storage
Crypto Pulse does not intentionally write plaintext API credentials to application logs. Portal credential responses are marked no-store, credential inputs use password fields and the form is cleared after a successful connection. Do not save exchange secrets in browser password managers, screenshots, chats or support messages.
Removal
The Remove stored API key control deletes credential material from the active database, revokes the portal connection and returns execution to signals-only mode. Encrypted credential material may remain in a restricted historical backup until that backup is rotated; it cannot be used by the active connection. Minimal non-secret metadata may remain for security and audit purposes. Revoke the original key on the exchange to invalidate it immediately everywhere.
Incident response
If a credential may have been exposed, revoke it immediately at the exchange before contacting support. Create a replacement dedicated key with withdrawals disabled and update the connection only after reviewing account activity.
Limits
Encryption and access controls reduce risk but cannot guarantee that a connected system will never be compromised. Crypto Pulse minimizes stored credential data, separates encryption material and provides immediate disconnection so members can reduce exposure.