Skip to content

Security

What ZML can and cannot do.

Where your keys live

Trade stores exchange API keys on your server. They are not transmitted to ZML, and ZML has no login to your machine. Z Market Lab uses its own read-only market data credentials and does not ask for yours.

No custody

ZML does not hold your funds. Orders go from your server to the exchange under your own API keys.

How updates work

Trade is closed-source software that updates itself. Releases assigned to your instance are applied automatically; every release is signed, verified before install, backed up first and rolled back if it fails. The software on your server is software ZML ships, so limit what any trading software can do with your keys.

Recommended precautions

  • Create API keys without withdrawal permission.
  • Restrict each key to your server's IP address.
  • Use a sub-account with only the capital you intend to deploy.
  • Keep server access to yourself. ZML will not ask for it.

What ZML receives from Trade

Instance identity, software version, machine name and public IP; operational health such as engine state and gateway connectivity; summary metrics for positions and combinations; and, once an hour, each combination's strategy parameters. This does not include API keys, exchange credentials or withdrawal addresses. The exact wording is the agreement Trade presents on first launch.

Admins never message first

Nobody from ZML will contact you first on Telegram, or ask for keys, passwords or funds. Treat any such message as fraud.

Who runs ZML

Z Market Lab is operated by an individual, not a company.

See it with real data.

Open the live demo without an account. Install Trade when you are ready to execute on your own server.

Live development