TradentDocs
Open app

Security

Threat model and audits

What could go wrong, in plain language, and how bad each case is. Plus an honest account of what has been independently audited (and what has not), and what we do not offer: insurance and guarantees.

A threat model is a list of ways things can fail and what the damage would be. We publish ours because "it is secure" is not an answer. The design goal is simple: a failure of Tradent's systems should be able to make you lose money by bad trading, but not let anyone take your money out.

What could go wrong#

Threat model in plain language
If this happensWhat an attacker could doWhat they could not do
One agent's key leaksPlace and cancel orders on that one user's account until you revoke it. That includes trading badly on purpose, for example crossing the spread repeatedly.Withdraw, deposit or change the account's controller. Funds can be lost through trading but cannot be taken out.
The sponsor wallet (fee payer) leaksSpend the SOL in itTouch any user account or agent key. It has no authority anywhere.
The master encryption key leaksNothing on its ownDecrypt anything without a copy of the database
The database leaksRead addresses, which key belongs to which account, and activityDecrypt the keys (they are encrypted), or move money
Master key and database both leakThe worst case: trade-only control of every delegated accountWithdraw anything. Every agent key would be rotated and users asked to re-delegate.
Our trading workers are compromisedRequest policy-approved orders for any live agent, bounded per order, per minute and per dayGet a withdrawal, deposit, transfer or delegation signed. The signing service refuses those before any key is touched.
Our website is compromisedDisrupt the service, revoke keys (a denial of service), or show you a malicious transaction to approveSign agent trades, or use the sponsor wallet to withdraw to someone else's address
Our database is written to by an attackerRevoke keys, or tamper with which market an order targetsForge a working key, or make the signing service sign a fund movement (those rules are code, not data)
Your login is taken overApprove a withdrawal as youNothing more than you could do yourself. Protect your login.
You are phished or your exported key leaksEverything, as it is your key-
Tradent disappears-Hold your funds hostage. You can export your key and withdraw on Phoenix directly.
The exchange (Phoenix) fails or is hackedDepends on the failure. Funds in your trading account are at risk.-

The honest residual risks are the ones in the table that involve the exchange and your own login: a bug or exploit at the exchange, a compromised login, a leaked exported key. Those are not things Tradent's design can remove.

What has been audited#

Audit status
ComponentStatusDetail
Tradent code (website, trading engine, signing service)Not externally auditedReviewed and tested by us only. Plans for a third-party review are to be announced.
Phoenix perpetuals program and exchangeNo public audit of the perps program was foundWhen we researched Phoenix (September 2026) we found a public audit only of its earlier spot product, a different program. Whether the perps program, Flight (builder fees) and Ember (the USDC wrapper) have been audited is an open question we have put to Phoenix. Flight is described by Phoenix as beta.
Privy (wallet provider)Third-party serviceWe rely on Privy's security for key sharding and the secure environment. We have not audited it, and its own security documentation is the place to read about it.
Transaction layoutsTested against the deployed programsEvery transaction we build was executed against copies of the real exchange programs in a simulator and checked against the live network without sending funds. This is testing, not an audit.

What we do not offer#

  • No insurance. There is no insurance fund or coverage for losses, hacks or exchange failure.
  • No guarantees. No guarantee of profit, of performance, of uptime, or of how quickly a withdrawal is paid.
  • No deposit protection. Funds in your wallet and trading account are not covered by any government or industry scheme.
  • No advice. Nothing on Tradent is investment, financial, legal or tax advice. Agents are software making automated decisions.

What we do to reduce risk#

  • Keys live in one small signing service on a private network. The website and trading workers hold none.
  • Every signing request is checked and logged, signed or refused.
  • Small pilot caps on position size and order size, daily budgets on sponsored fees, rate limits, and a kill switch.
  • Your own risk limits, daily-loss and drawdown brakes, and keeper-enforced stop-losses.
  • A documented incident runbook for rotating keys and pausing trading.

Found a vulnerability? Please tell us privately before making it public. See Status and support for how to reach us.