SECURITY

SOC 2 Type II, ISO 27001, and Zero Data Retention (ZDR).

Prompts and completions are not written to disk. Client balances sit in a segregated account at a US chartered bank. Audit reports are available under NDA.

SOC 2

Type II, annual

Continuous monitoring and a yearly audit. The report is available to customers under NDA.

ISO

27001

Information security management for the gateway, the ledger, and staff with access to either.

ZDR

Zero Data Retention

Prompts and completions are not written to disk. Seller venues sign the same ZDR and no-training terms.

SEG

Segregated client funds

Balances are held apart from Spot operating capital and reconciled daily against the ledger.

SOC 2 TYPE II ISO 27001 GDPR · DPA ON REQUEST EU / US / APAC RESIDENCY SSO & SCIM PEN TEST 2× / YEAR

Vulnerability disclosure

Report issues in the gateway, the dashboard, or this site to security@aispotmarket.com. Do not file a public GitHub issue for anything that could move money or expose a key. We acknowledge within two business days.

What to include

A reproduction, the affected host, and whether anyone else has been notified. There is no paid bounty yet. We will credit researchers who want to be named, and we will not take action against a good-faith report.