Security

Non-custodial.
By design.

We never hold your funds. We never see your private key. We don’t need to. Here’s exactly how a TP/SL fires without us ever touching your wallet.

Keys never leave the secure enclave.

When you onboard, we provision a Polymarket trading key via Privy (the same infrastructure used by Friend.tech, Hyperliquid, and dozens of production DeFi apps). The private key is generated inside an AWS Nitro Enclave and stored encrypted. We can request signatures from it — we can never extract it.

Every order is a scoped signature.

When your TP triggers, our worker submits a signed EIP-712 order to Polymarket’s CLOB. The signature authorises exactly one trade — token, side, size, price. There’s no blanket approval, no “allow the bot to drain my wallet” permission, and no path for us to move funds anywhere except the Polymarket order book your wallet already had access to.

We store the minimum.

We store: your wallet address, your active brackets, your alert preferences, your Telegram link (if you opt in), and an append-only log of the actions our worker took on your behalf. We do not store: passwords, recovery phrases, or anything that could let someone else trade as you. Our database is hosted on Supabase in the EU.

Audit trail you can read.

Every bracket has an Activity tab showing every order our worker submitted on its behalf — timestamp, filled size, average fill price, the raw CLOB response. The bracket also surfaces a forensic lifecycle log of every state change. If you ever want to know exactly what the bot did and when, the answer is in the bracket detail.


Responsible disclosure

If you find a security issue, email us at contact@unusualbets.com with the subject line SECURITY. We acknowledge within 48 hours and aim to patch critical issues within seven days.