WORKSPACE

Security architecture

EXECUTION • CONTROLLED
SECURITY + CONTROL

Protect the execution path, not just the login.

URBOT is designed so a TradingView alert does not become a broker order until it has passed authentication, interpretation and risk checks.

01CREDENTIALSExchange credentials are handled server-side, encrypted before storage and kept out of TradingView messages.
02AUTHENTICATIONEach bot has its own webhook secret. Requests without the correct secret are rejected before processing.
03INTERPRETATIONURBOT separates the incoming alert from the trading action. Unmapped indicator values, shapes or text can remain observations.
04RISK ENGINEBot status, allocation, direction, leverage, duplicate events and configured protection are checked before execution.
05EXECUTION QUEUELive signals are queued for a guarded worker instead of relying on the browser to place broker orders.
06AUDIT + RECONCILIATIONWebhook events, broker orders, positions and reconciliation activity are recorded so the lifecycle can be inspected.

Recommended connection permissions

Read / accountRequired where the provider uses account information for validation or sizing.
TradeRequired for live order submission on supported adapters.
WithdrawalsKeep disabled. URBOT does not implement withdrawal functionality.

What you can verify

01SIGNALReceived + authenticated
02DECISIONInterpreted + risk checked
03ORDERQueued + broker status
04POSITIONEntry / protection / P&L
05AUDITLifecycle recorded
Security is not a guarantee. Controls reduce operational risk but cannot guarantee exchange availability, network delivery, market behaviour or profitable trading. Test in paper mode, use least-privilege API permissions and monitor live execution.