Security & Trust

Your Security Is
Our Foundation

We built SmartViewAI on a single principle: analyse everything, control nothing. We see your portfolio data so our AI can surface insights , we never touch your assets.

Start Tracking Safely

How We Protect You

Every layer of SmartViewAI is designed around the assumption that you should never have to trust us with custody of your funds.

Read-Only API Keys

We only request read permissions from your exchange. No withdrawals, no trades, no transfers , ever. This is enforced at the API scope level, not just a setting we control.

Zero Custody

We never hold your crypto. Your assets stay on your exchange at all times. SmartViewAI has no wallets, no addresses, and no ability to move funds on your behalf.

SSL / TLS Encryption

All data is transmitted over 256-bit TLS encryption. Your API keys and secrets are encrypted at rest using AES-256 before they ever reach our database.

No Withdrawal Permissions

Our API scopes explicitly exclude withdrawal and trading permissions. This is enforced at the exchange level , not just our policy. Even if our systems were compromised, no funds could move.

Data Privacy

We do not sell your data. Your portfolio composition, holdings, and trading history are visible only to you and the AI models powering your personal analytics. We are GDPR aware.

Secure Authentication

JWT-based sessions, optional two-factor authentication, and automatic session expiry protect your account. httpOnly cookies prevent client-side token exposure.

Verify Read-Only Permissions Yourself

You do not have to take our word for it. Every major exchange lets you inspect your API key permissions directly. Here is how to confirm read-only access on the exchanges we support.

Binance Go to Account → API Management, select your key, and confirm only Read Info is checked , Enable Spot & Margin Trading must be off.
Bybit Go to Account → API → My API Keys and verify the key shows Read-Only under Permissions with no Trade or Withdraw access.
OKX Navigate to Profile → API, open the key details, and ensure only Read permission is listed , Trade and Withdraw should be absent.
KuCoin Open Account → API Management, view the key, and confirm permissions show only General , Trade and Transfer must be disabled.

Frequently Asked Questions

Still have questions about how we handle your security? We have answers.

Can SmartViewAI make trades on my behalf?
No. Read-only API keys technically cannot place orders at the exchange level. Even if our code attempted to initiate a trade , which it does not , the exchange would reject the request outright because the key scope does not permit it.
What happens if I revoke my API key?
Your data is immediately disconnected the next time a sync is attempted. Any cached portfolio snapshot is retained until you choose to delete it from your profile. You can remove all associated data permanently from Account Settings at any time.
Do you store my exchange API secret?
Yes , but securely. API secrets are encrypted using AES-256 before storage and are never written to application logs. The plaintext secret exists in memory only for the duration of an API call, then is discarded. Our engineering team does not have access to read decrypted secrets.
Is my portfolio data shared with third parties?
Never. Your data is used only to power your personal analytics and AI insights. We do not sell, rent, or share portfolio composition data with advertisers, data brokers, or any external party. Aggregated, anonymised market trend data may be used to improve our AI models.
SSL Secured
Read-Only Only
Zero Custody
GDPR Aware

Start Tracking Safely

Connect your exchange in under two minutes. Read-only. No risk. Full insight.

Create Free Account