Security
Threat model and audits
What could go wrong, in plain language, and how bad each case is. Plus an honest account of what has been independently audited (and what has not), and what we do not offer: insurance and guarantees.
A threat model is a list of ways things can fail and what the damage would be. We publish ours because "it is secure" is not an answer. The design goal is simple: a failure of Tradent's systems should be able to make you lose money by bad trading, but not let anyone take your money out.
What could go wrong#
| If this happens | What an attacker could do | What they could not do |
|---|---|---|
| One agent's key leaks | Place and cancel orders on that one user's account until you revoke it. That includes trading badly on purpose, for example crossing the spread repeatedly. | Withdraw, deposit or change the account's controller. Funds can be lost through trading but cannot be taken out. |
| The sponsor wallet (fee payer) leaks | Spend the SOL in it | Touch any user account or agent key. It has no authority anywhere. |
| The master encryption key leaks | Nothing on its own | Decrypt anything without a copy of the database |
| The database leaks | Read addresses, which key belongs to which account, and activity | Decrypt the keys (they are encrypted), or move money |
| Master key and database both leak | The worst case: trade-only control of every delegated account | Withdraw anything. Every agent key would be rotated and users asked to re-delegate. |
| Our trading workers are compromised | Request policy-approved orders for any live agent, bounded per order, per minute and per day | Get a withdrawal, deposit, transfer or delegation signed. The signing service refuses those before any key is touched. |
| Our website is compromised | Disrupt the service, revoke keys (a denial of service), or show you a malicious transaction to approve | Sign agent trades, or use the sponsor wallet to withdraw to someone else's address |
| Our database is written to by an attacker | Revoke keys, or tamper with which market an order targets | Forge a working key, or make the signing service sign a fund movement (those rules are code, not data) |
| Your login is taken over | Approve a withdrawal as you | Nothing more than you could do yourself. Protect your login. |
| You are phished or your exported key leaks | Everything, as it is your key | - |
| Tradent disappears | - | Hold your funds hostage. You can export your key and withdraw on Phoenix directly. |
| The exchange (Phoenix) fails or is hacked | Depends on the failure. Funds in your trading account are at risk. | - |
The honest residual risks are the ones in the table that involve the exchange and your own login: a bug or exploit at the exchange, a compromised login, a leaked exported key. Those are not things Tradent's design can remove.
What has been audited#
| Component | Status | Detail |
|---|---|---|
| Tradent code (website, trading engine, signing service) | Not externally audited | Reviewed and tested by us only. Plans for a third-party review are to be announced. |
| Phoenix perpetuals program and exchange | No public audit of the perps program was found | When we researched Phoenix (September 2026) we found a public audit only of its earlier spot product, a different program. Whether the perps program, Flight (builder fees) and Ember (the USDC wrapper) have been audited is an open question we have put to Phoenix. Flight is described by Phoenix as beta. |
| Privy (wallet provider) | Third-party service | We rely on Privy's security for key sharding and the secure environment. We have not audited it, and its own security documentation is the place to read about it. |
| Transaction layouts | Tested against the deployed programs | Every transaction we build was executed against copies of the real exchange programs in a simulator and checked against the live network without sending funds. This is testing, not an audit. |
What we do not offer#
- No insurance. There is no insurance fund or coverage for losses, hacks or exchange failure.
- No guarantees. No guarantee of profit, of performance, of uptime, or of how quickly a withdrawal is paid.
- No deposit protection. Funds in your wallet and trading account are not covered by any government or industry scheme.
- No advice. Nothing on Tradent is investment, financial, legal or tax advice. Agents are software making automated decisions.
What we do to reduce risk#
- Keys live in one small signing service on a private network. The website and trading workers hold none.
- Every signing request is checked and logged, signed or refused.
- Small pilot caps on position size and order size, daily budgets on sponsored fees, rate limits, and a kill switch.
- Your own risk limits, daily-loss and drawdown brakes, and keeper-enforced stop-losses.
- A documented incident runbook for rotating keys and pausing trading.
Found a vulnerability? Please tell us privately before making it public. See Status and support for how to reach us.