Security & Trust

Your funds and your data stay yours

MasterBitcoin is a signal service, not a custodian. We're built so that the worst case - even if we were compromised - never puts your money at risk.

Non-custodial by design

We never take custody of your funds. MasterBitcoin holds no deposits, processes no withdrawals, and has no ability to move your money. You trade on your own exchange account, in your own name.

No access to your exchange

We never ask for your exchange API keys, login, or trading permissions. Signals flow one way - from us to you. Your execution layer connects to your exchange independently of us.

Scoped, revocable API keys

When the API launches, your MasterBitcoin key grants read-only access to signal data and nothing else. Keys are personal, revocable at any time, and never expose account or financial controls.

Minimal data collection

We collect only what's needed to run your account: email, subscription status (via Stripe - we never store card details), and request logs for rate-limiting and abuse prevention.

Your data

A plain-English data promise

What we do

  • Use your email to operate your account and send the updates you opted into
  • Process payments securely through Stripe (PCI-compliant; we never see card numbers)
  • Keep short-lived request logs to enforce rate limits and detect abuse
  • Honour GDPR rights - access, export, and deletion on request

What we never do

  • Sell, rent, or share your personal data with third parties
  • Touch, hold, or move your funds - ever
  • Request your exchange credentials or trading permissions
  • Run cross-site advertising or tracking cookies

Infrastructure

The platform runs over HTTPS with modern security headers (CSP, HSTS-ready, clickjacking and MIME-sniffing protection). Payments are handled entirely by Stripe. Secrets are kept server-side and never exposed to the browser.

Responsible disclosure

Found a vulnerability? We want to hear from you. Email support@masterbitcoin.com with details and steps to reproduce. Please give us a reasonable window to remediate before any public disclosure.

A note on honesty: we're an independent team in our validation phase, not a regulated financial institution. We don't hold formal certifications like SOC 2 yet, and we won't claim ones we don't have. As we grow, we'll pursue and publish the right ones - and update this page when we do.