Security
Coinomatic security model
Coinomatic is designed as an execution layer for rules in your own exchange account. Security begins with limiting what the connection can do.
No custody
Coinomatic does not receive private wallet keys, pool customer funds or operate an on-chain wallet. Exchange-side actions occur in the account you control.
Scoped exchange credentials
The Kraken integration needs only the permissions required by the configured workflow. You can revoke access by disabling the API credential at the exchange.
Protected storage and audit trail
Stored API credentials are encrypted at rest and access is restricted. When a workflow executes, the service must use the credential in process to make the authorized exchange request. Runs, skips and failures are recorded for review.
Report a security issue
Send responsible security reports to info@coinomatic.io. Do not include active API credentials, passwords or other secrets in the first message.