Security & custody
What we can do with your key, and what we cannot.
PolyPilot is not a fund and holds no balance for you. What it holds is an encrypted signing key, and this page is the complete, unflattering account of what that means — including the part most services leave out.
Security & custody
The uncomfortable part, said plainly.
To place an order on Polymarket, something has to sign it with your wallet key. Polymarket does not issue a trade-only credential — so a service that copies trades for you necessarily holds a key that could also move funds. Anyone telling you otherwise is describing software that cannot work.
We would rather you knew that before you decide, not after.
Our advice: connect a Polymarket account funded with only what you intend to have in play, and keep your long-term holdings somewhere this service has never touched.
You never have to hand over a key
The free plan and the Signals plan both show you the scored feed and ask for nothing but an email address — Signals in real time, across all 100 tracked wallets. You place the trades yourself on Polymarket. Copying is the only thing that needs a key, and it is entirely optional.
- Encrypted at rest
- AES-256-GCM with a unique initialisation vector per record. The master key lives only in the deployment environment, never in the database — a stolen database dump cannot sign a single order.
- Decrypted only to sign
- Your key is unsealed in memory at the moment an order is signed and discarded straight after. It is never written to a log, never returned in an API response, and never reaches your browser after you submit it.
- Order placement only
- The software calls exactly one thing on your behalf: place a fill-and-kill limit order. There is no code path in this product that transfers, withdraws or approves tokens.
- Removable in one click
- Disconnecting wipes the stored envelope and switches auto-pilot off in the same write. Nothing is retained for “convenience”.
Capability boundary
Four things, stated as limits.
Two the software does. Two it has no ability to do — not switched off, not permission-gated, simply absent from the codebase.
Place a fill-and-kill limit order
This is the only action the software takes on your behalf. It is bounded by your own per-trade cap, your slippage ceiling and your daily limit, all enforced on the server.
Read your public positions and balance
So the dashboard can show what you hold and refuse a copy you cannot fund. This data is public on chain regardless of whether you use this service.
Transfer, withdraw or bridge funds
There is no code path in this product that moves tokens out of your account. Not a disabled feature — no such function exists to call.
Approve token spending to a third party
No approval transactions are ever constructed or signed. The only signatures produced are order signatures for the Polymarket CLOB.
Residual risk
What good engineering does not fix
Encryption protects a stolen database. It does not protect against a compromise of the running environment, because a server that can sign your orders is by definition a server that can decrypt your key. That is the irreducible trade in any service of this kind, and no amount of security copy changes it.
So the meaningful protection is not cryptographic, it is positional: connect an account holding only what you intend to trade. If the worst happened, the ceiling on your loss is the balance in that account — a limit you set, enforced by arithmetic rather than by our promises.
We would rather write that down plainly than let a page of security badges imply a guarantee nobody in this category can actually make.
Questions
Asked before handing over a key.
Why do you need a private key at all?
Polymarket's order book requires every order to be signed by the wallet placing it, and Polymarket does not issue a trade-only API credential. Any service that places orders for you therefore holds a key that could technically also move funds. A service claiming otherwise is describing something that cannot work.
How is the key stored?
AES-256-GCM, with a unique initialisation vector per record. The master key exists only in the deployment environment and is never written to the database, so a stolen database dump contains ciphertext that cannot be used to sign anything.
Does my key ever reach the browser again?
No. After you submit it, it is encrypted server-side and never returned in any API response. The dashboard only ever shows you a masked public address derived from it.
What is the safest way to use this?
Fund a Polymarket account with only the capital you intend to have in play, and connect that one. Keep long-term holdings in a wallet this service has never seen. This is the single most effective thing you can do, and it costs you nothing.
What happens when I disconnect?
The encrypted envelope is deleted and auto-pilot is switched off in the same write. Nothing is retained, and there is no soft-delete or grace period.
Can I use the product without giving you a key?
Yes. The free plan shows you the full scored signal feed on a 15-minute delay and never asks for a key. You can follow the calls manually on Polymarket indefinitely.
Something here not answered? Ask before you connect anything. Signed-in customers can also message us from the Support panel in the dashboard.
