Security
VScalp is software, not a custodian. You keep your funds on your exchange, you manage your own API permissions, and you can pause or disconnect at any time.
Last updated: August 2026
1. Software-only and non-custodial
VScalp provides signal intelligence, automation rules and analytics tools. We do not provide trading, custody, wallet, brokerage or investment advisory services. All order execution, custody of funds and settlement happen on the third-party exchange to which you connect your own API key.
We do not hold user deposits, operate pooled accounts, or have any ability to withdraw or transfer funds from your exchange account. Your API keys are scoped by you on the exchange, remain revocable by you at any time, and can be deleted by you from VScalp at any time.
2. What VScalp does and does not do
What VScalp does
- Read market data and, with your permission, account data from your exchange.
- Apply the rules you configure to generate signals and, when enabled, submit orders to your exchange.
- Log every signal, decision, order request and error so you can review what happened.
- Encrypt the exchange API secrets you provide at rest, and transmit data over HTTPS/TLS.
What VScalp does not do
- Hold, pool, insure or guarantee your funds.
- Make discretionary investment decisions or promise any return.
- Withdraw or transfer assets from your exchange account.
- Access your exchange account without an API key you explicitly create and provide.
3. API permissions and scope
When you connect a Bybit account, you create the API key on Bybit and decide which permissions it has. VScalp reads only what those permissions allow, and it cannot exceed the scope you set. We recommend the minimum permissions needed for the feature you use:
- Read-only access — for account monitoring, PnL reporting and trade history. This is sufficient for Copy Bybit visibility and performance analytics.
- Spot / Derivatives trading permission — only required if you enable Auto-Trade. This lets VScalp submit orders on your behalf according to the rules you save.
- Withdrawal permission must never be enabled for the API key you connect to VScalp. VScalp does not need it and will never ask for it. Enabling withdrawal permission creates an unnecessary risk.
You can review, restrict or revoke the key at any time from your Bybit account settings. Revocation takes effect immediately and stops VScalp from reading or trading on that account.
4. Where your funds remain
Your assets stay in your own exchange account. VScalp has no omnibus wallet, no custody agreement and no authority to move funds. If you use Auto-Trade, VScalp sends order instructions to the exchange; the exchange matches, clears and settles those trades inside your account. If you use Copy Bybit, replication is performed by Bybit's own copy-trading infrastructure, not by VScalp.
5. Your controls: pause, disconnect and review
You remain in control of the following actions at all times:
- Pause execution — the Auto-Trade execution switch stops VScalp from submitting new orders while it is off. Existing open positions remain on your exchange account and are managed by you or the exchange.
- Disconnect an account — deleting the API key from VScalp removes it from our system. To fully revoke access, delete or disable the key in your Bybit account as well.
- Change rules — per-account and per-bot settings such as order size, take-profit, stop-loss, DCA levels and leverage are set by you and apply only to the account you select.
- Review logs — the Auto-Trade decision logs, webhook delivery logs and DCA cycle audit views record what the software did and why.
6. Logging, monitoring and audit
VScalp records the metadata of every automated decision, including the signal that triggered it, the rule values that were applied, the order request sent to the exchange, and any error or skip reason. These logs are available to you in the Auto-Trade and admin audit sections. They are retained for a limited period for debugging, support and dispute resolution.
We also monitor application health, error rates and security alerts. We do not log or store your exchange password or withdrawal credentials.
7. Security practices and limitations
We use standard technical and organizational measures to protect the Service. Specifically: traffic between your browser, our servers and the exchange APIs is served over HTTPS/TLS; exchange API secrets you provide are encrypted at rest with AES-GCM before storage; access to admin and account-scoped data is enforced through role-based checks and database row-level security policies; and dependencies are scanned automatically for known vulnerabilities on a scheduled basis, with high or critical advisories failing the build.
To be precise about scope: we have not published a third-party penetration test, security certification or formal audit report, and the scanning described above covers software dependencies rather than the full infrastructure. These measures reduce risk but do not eliminate it.
Security is not the same as trading safety. Even with correct API permissions and sound software, futures and leveraged trading can result in losses that exceed your margin. Software bugs, exchange outages, market gaps, network delays and incorrect user configuration can all lead to outcomes that differ from what you expected. Security practices help protect access and data; they do not remove market or operational risk.
8. Questions or reports
If you have a security concern or believe you have found a vulnerability, please contact us at help@vscalp.me. We will review reports and respond as promptly as we can. Please do not test against production accounts or data belonging to other users.
9. Read more
For the legal terms governing your use of the Service, see our Terms of Use, Privacy Policy, Cookie Policy and Risk Disclosure.