Security

Built for trust from day one

Your Phantom wallet is never at risk. We designed Gigabot so that the most sensitive thing it ever touches is a one-time sign-in message — and a bot wallet that only holds what you deliberately deposit.

Security model

How we protect you

Sign-In With Solana (SIWS)

Auth

Authentication uses your Phantom or Solflare wallet to sign a unique nonce message. We verify the cryptographic signature on our server — we never see, store, or transmit your private key. There is no password to leak.

Separate bot wallet per user

Isolation

Gigabot creates a dedicated trading wallet that is separate from your Phantom. You choose how much SOL to deposit. If anything ever went wrong, your main wallet is completely unaffected.

AES-256-GCM encryption at rest

Encryption

Your bot wallet's private key is encrypted with AES-256-GCM before being stored in the database. The master encryption key is loaded from the server environment — it is never in the database and never exposed to clients.

Non-custodial sign-in, custodial trading

Custody model

Your personal Phantom wallet signs nothing except the SIWS login message. Only the Gigabot bot wallet signs trade transactions — and it only holds funds you deliberately deposited.

Roadmap

Security roadmap

We're transparent about where we are and where we're going.

SIWS authentication — no passwords
Per-user isolated bot wallets
AES-256-GCM key encryption (env-based, dev)
Devnet deployment — no real funds at risk
Hardware Security Module (HSM) / KMS for production key management
Planned
Mainnet launch after KMS is verified
Planned
Independent security audit
Planned

Important disclaimer

Gigabot is currently running on Devnet — no real funds are at risk. The current key storage implementation (AES-256-GCM, env-based) is suitable for development only. Before any mainnet launch, we will complete a KMS/HSM migration and independent security audit. Copy trading involves financial risk regardless of security. Past performance of mirrored wallets does not guarantee future results. This is not financial advice.

Start copy trading in seconds.

Connect your Phantom or Solflare wallet — no account needed.

Connect Wallet