Security by construction

We can't move your money.
By design.

The biggest risk in any trading service is the platform itself. Glimpse is built so that even a worst-case breach on our side cannot cost you a single dollar. Here's how that works in plain English.

01 · Trading-only access

We can place trades. We cannot move money.

When you connect Bybit or Toobit, Glimpse only accepts a trading-only API key. Withdrawals are blocked at the source. Even if every part of our system were compromised tomorrow, no attacker could move funds out of your account through us.

  • Trade · place and close orders
  • Read · positions and balances
  • Withdraw · refused at signup
  • Transfer · refused at signup
02 · Encrypted at rest

Your keys are sealed before they touch storage.

The keys you give us are encrypted the moment we receive them, with industry-standard authenticated encryption. They're only decrypted in memory, briefly, when the desk needs to place a trade — never written to a log, never returned to your browser, never copied to a backup in the clear.

  • Authenticated encryption (tamper-evident)
  • Master key isolated from the database
  • Plaintext only ever exists in memory, briefly
  • Zero key material in logs or analytics
03 · No custody, ever

Your money lives at your exchange.

Glimpse is not a custodian. Your funds sit on your own Bybit or Toobit account at all times. We never hold a balance on your behalf. If we were to vanish tomorrow, you log into your exchange and trade as you always could. No bridge to unwind. No queue to wait through.

  • You hold the credentials to your exchange
  • You can revoke our key in one click
  • Pause stops the desk instantly — no lock-up
04 · Per-user isolation

Your data stays yours. Enforced at the database.

Every read and write is gated at the database level: you can only see your own rows. That isn't a check we run in code that we could forget — it's built into the data layer. Even if a bug slipped through review, the database itself refuses to leak another customer's data.

  • Database-level access control on every table
  • Privileged access scoped to specific server routes only
  • Browser sessions can only ever read your own data
05 · Encrypted in transit

No plaintext on the wire.

Every connection — to your browser, to your exchange, to our payment processor — runs over modern encrypted transport. Every order request is signed and verified. Every payment notification is signature-checked before we trust it.

  • Modern TLS, HSTS-preloaded
  • Signed and verified order requests on every trade
  • Signed and verified payment notifications
06 · Fail-closed defaults

When in doubt, the desk doesn't trade.

Service issue on our side? The desk pauses. Exchange unreachable? Orders queue and retry, with the user notified. Conditions deteriorate mid-trade? The desk tightens to flat instead of pressing. Empty days are cheaper than wrong days.

  • Outage on our side → desk pauses, no replay
  • Exchange degraded → backoff, retry, alert
  • Anomalous conditions → no new entries until clear
Responsible disclosure

Found something?

We have a no-questions-asked vulnerability disclosure policy. If you find a security issue, write to us before publishing it. We'll respond within one business day, fix promptly, and credit you publicly if you'd like.

Email
security@glimpse.trading
PGP key on request
Response time
< 24h
Business days, EU timezone
Bounty
Case-by-case
Cash and public credit