AlgoVesta › Glossary › Encryption at rest (AES-256)

Platform & Security

Encryption at rest (AES-256)

Encryption at rest means data stored on disk or in a database, such as exchange API secrets, broker passwords and session tokens, is kept in encrypted form and only decrypted in memory when it is needed; AlgoVesta uses AES-256 for this, with keys held separately from the data.

Why it matters

Trading platforms hold the most sensitive credentials a trader has. A database backup, a disk image or a misconfigured server exposes every stored secret at once if they are stored in plain text. Encryption at rest means a copy of the data alone is useless without the key, and it lets the platform enforce that decryption happens only in the specific code path that needs the secret, for example when signing an order. It does not by itself protect against a compromise of the running server, which is why it is combined with trade-only key scopes and IP restrictions.

How AlgoVesta handles it

AlgoVesta stores exchange API keys, MetaTrader passwords and Telegram session material encrypted with AES-256, and the encryption binds each secret to the account it belongs to so a record cannot be decrypted under a different account. Secrets are decrypted in memory only where they are used, by the execution path that signs an order or the terminal that logs in, and are never written to logs or shown in the dashboard after entry; the interface shows only a label and the last characters of a key. Decryption failures are counted and raise an internal alert rather than being silently skipped, because a monitor that cannot decrypt a key would otherwise fail without anyone noticing. Combined with trade-only scopes, exchange-side IP restrictions and the non-custodial model, a leaked record cannot move funds. See the Security page and the trade-only API key entry.

Example

A user pastes a Bybit key and secret into the dashboard. The secret is encrypted with AES-256 and stored; from then on the dashboard shows only "Bybit main · ...7f2a". When a signal arrives, the execution server decrypts the secret in memory, signs the order request, and discards the plaintext. If the database were copied, the attacker would hold ciphertext without the key.

Common mistakes

In practice

See how AlgoVesta automates this