01 · Trading-only accessWe can place trades. We cannot move money.
When you connect Bybit or Toobit, Glimpse only accepts a trading-only API key. Withdrawals are blocked at the source. Even if every part of our system were compromised tomorrow, no attacker could move funds out of your account through us.
- Trade · place and close orders
- Read · positions and balances
- Withdraw · refused at signup
- Transfer · refused at signup
02 · Encrypted at restYour keys are sealed before they touch storage.
The keys you give us are encrypted the moment we receive them, with industry-standard authenticated encryption. They're only decrypted in memory, briefly, when the desk needs to place a trade. Never written to a log, never returned to your browser, never copied to a backup in the clear.
- Authenticated encryption (tamper-evident)
- Master key isolated from app storage
- Plaintext only ever exists in memory, briefly
- Zero key material in logs or analytics
03 · No custody, everYour money lives at your exchange.
Glimpse is not a custodian. Your funds sit on your own Bybit or Toobit account at all times. We never hold a balance on your behalf. If we were to vanish tomorrow, you log into your exchange and trade as you always could. No bridge to unwind. No queue to wait through.
- You hold the credentials to your exchange
- You can revoke our key in one click
- Pause stops the desk instantly. No lock-up
04 · Per-user isolationYour data stays yours. Enforced below the app.
Every read and write is gated below the interface: you can only see your own records. That isn't a screen-level check we could forget. It is built into the private data layer, so a bug in the app still cannot expose another customer's information.
- Per-user access control on every private record
- Privileged access scoped to specific server paths only
- Browser sessions can only ever read your own data
05 · Encrypted in transitNo plaintext on the wire.
Every connection (to your browser, to your exchange, to our payment processor) runs over modern encrypted transport. Every order request is signed and verified. Every payment notification is signature-checked before we trust it.
- Modern TLS, HSTS-preloaded
- Signed and verified order requests on every trade
- Signed and verified payment notifications
06 · Fail-closed defaultsWhen in doubt, the desk doesn't trade.
Service issue on our side? The desk pauses. Exchange unreachable? Orders queue and retry, with the user notified. Conditions deteriorate mid-trade? The desk tightens to flat instead of pressing. Empty days are cheaper than wrong days.
- Outage on our side → desk pauses, no replay
- Exchange degraded → backoff, retry, alert
- Anomalous conditions → no new entries until clear