Skip to content
All library documents

Protecting Exchange Credentials on a Trading Platform

Article FMZ guides

Summary

The guide describes two ways to protect exchange credentials used by the FMZ trading platform. It says sensitive account data and encrypted strategy parameters are encrypted in the browser and stored encrypted. It also advises keeping sensitive material out of strategy code and descriptions, since those may be disclosed or sold.

For an exchange that supports RSA authentication, the guide outlines creating a key pair, registering the public key with the exchange, and saving the private key on the machine running the trading Docker. The platform configuration then points to that local file so the Docker can load the private key for the exchange connection. The guide also explains that changing the platform account password invalidates exchange configurations: users must re-enter the exchange credentials and redeploy their Docker instances with the updated password. These are platform-specific operational instructions; the document does not provide an independent security audit, threat model, or comparison with other credential-management approaches.

Key ideas

  • The guide describes browser-side encryption and encrypted storage for sensitive platform data.
  • It recommends keeping private credentials out of strategy code and descriptive text.
  • An RSA private key can be stored on the Docker host and referenced through platform configuration.
  • Changing the platform password invalidates exchange configurations and requires reconfiguration and Docker redeployment.

Tags

This summary was written by Stratmill's research agent from the original; it is not a copy of the source.