> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mirrortrade.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & custody

> Your funds stay in your account. MirrorTrade gets permission to trade, not withdraw.

<img src="https://mintcdn.com/alpha-you/RES9X29rHVMsOQzE/images/security-architecture.png?fit=max&auto=format&n=RES9X29rHVMsOQzE&q=85&s=7621dd48eabf5676d98d8f90f21cfb40" alt="Your wallet approves MirrorTrade’s encrypted agent key to trade in your Hyperliquid account. Withdrawals require your wallet. Encryption, address checks and a signing guard protect agent-key use." width="1200" height="600" data-path="images/security-architecture.png" />

## Your funds stay yours

Your funds sit in your own copy account on Hyperliquid, not with MirrorTrade or the trader you follow. Your user-owned Privy wallet authorizes withdrawals. A separate agent key lets MirrorTrade copy trades while you are offline.

## How the trading key is protected

* **Encrypted storage.** Agent keys are encrypted with AES-256-GCM before storage.
* **Address checks.** Before use, the engine checks that the key matches the agent address recorded for your account.
* **Restricted signing.** The copy engine allows supported trading actions and rejects withdrawals and transfers.

The key is decrypted in server memory to trade. Encryption protects stored keys; it does not eliminate the risk of a compromised server.

## How to remove access

1. Use the correct copy wallet to revoke its agent through Hyperliquid.
2. If you enabled agent-renewal delegation, remove that permission too. It can approve a replacement agent.
3. Review open orders and positions. Revoking access does not close positions or cancel every order.

Pausing or signing out does not revoke access. Secure your wallet login and verify recovery or export access through Privy before you need it. Never share keys or seed phrases.

## What still carries risk

A trading key cannot withdraw, but it can place losing trades. Losses, liquidation, wallet compromise and Hyperliquid protocol or bridge failures remain possible. Non-custodial does not mean risk-free.

## Sources and support

Checked against the implementation on September 26, 2026; not an independent security audit.

* [Hyperliquid API wallets](https://hyperliquid.gitbook.io/hyperliquid-docs/for-developers/api/nonces-and-api-wallets)
* [MirrorTrade security explainer](https://mirrortrade.co/blog/mirrortrade-security-non-custodial-key-management)

Security issue? Contact [info@mirrortrade.co](mailto:info@mirrortrade.co). Never include keys or seed phrases.
