1. Current and planned controls
Current internal controls must be distinguished from planned commercial controls. Planned controls include client isolation, encrypted secrets, 2FA, RBAC, audit logs, monitoring, backups and incident response.
2. API permissions
Final permissions are [FINAL API PERMISSIONS]. Withdrawal permissions are not required and must not be supplied. API secrets must never appear in frontend code or local browser storage.
3. Shared responsibility
WHITE ROCK / AUREXIS is responsible for the defined product environment. Customers remain responsible for exchange account security, authorized users, endpoint security, configuration and prompt reporting of suspicious activity.
4. Vulnerability reporting
Security reports should be sent to [SECURITY EMAIL] with reproducible details. Do not access data that is not yours, disrupt service, or publicly disclose an issue before coordinated review.
5. Incident response
Commercial release requires defined severity levels, containment, recovery, customer notification, evidence retention and post-incident review.
Crypto and derivatives trading involves substantial risk. Losses are possible. Past performance does not predict future results. No outcome is guaranteed. AUREXIS does not provide investment advice. The user remains responsible for configuration, capital and risk decisions. The connected exchange remains the source of truth.