Your data. Never your money.
Confluovest exists to show you your portfolio — not to touch it. This page explains exactly what we can access, how it's protected, and what control you keep.
Read-only by design
Confluovest is a tracker, not a broker. There is no code path in the product that places a trade, moves funds, or initiates a withdrawal — not hidden behind a setting, not planned for later. This is a deliberate product decision, not just a feature gap: it keeps your assets untouchable and keeps Confluovest out of the business of handling money.
When you connect Binance, you create API keys with read-only permission — Binance itself enforces that those keys cannot trade or withdraw, independently of anything we do. Our setup guide walks you through creating them correctly, and we verify the key's permissions when you connect. If a key has more permission than we need, we tell you and ask you to replace it.
What we can and cannot do
Confluovest CAN
- Read balances and holdings on connected accounts
- Read your transaction history to build your ledger
- Read CSV files you choose to upload
- Fetch market prices and FX rates to value your portfolio
- Delete your data when you ask
Confluovest CANNOT
- Place, modify, or cancel any trade
- Withdraw, transfer, or move funds — anywhere, ever
- Access platforms you haven't connected
- See your login passwords for Binance or any brokerage
- Sell your personal data (we don't, full stop — see Privacy Policy)
How your keys and data are stored
- Encryption at rest. API keys are encrypted with AES-256 before they are stored. Nobody at Omareon Labs can read your raw keys.
- Encryption in transit. All traffic between your browser, our servers, and connected platforms uses TLS 1.2+.
- Passwords. Your Confluovest password is hashed with an industry-standard algorithm (bcrypt); we never store or see it in plain text.
- Isolation. Confluovest runs on its own infrastructure with its own database — not shared with any other product.
- Least privilege internally. Administrative access is limited, individually authenticated with two-factor authentication, and every privileged action is written to an immutable audit log.
You stay in control
- Disconnect any source, any time. Removing a source deletes its stored API key immediately.
- Revoke from the platform side too. Because keys are created in your Binance account, you can also revoke them there at any moment — Confluovest's access dies with the key.
- Export your data. Holdings and transactions export to CSV whenever you want. It's your data.
- Delete everything. Account deletion permanently removes your profile, connected sources, holdings, transactions, imports, and reports. Available in-app or by request — see the Privacy Policy for the process and NDPR basis.
What we won't claim
Security pages love absolutes; we'll avoid them. No system is unbreachable, and a young product should say so. What we commit to: encryption as described above, read-only scope enforced at the platform level, no selling of personal data, prompt disclosure if an incident ever affects your data, and deletion that actually deletes. If you find a vulnerability, email security@confluovest.com — we read every report and respond.
[PLACEHOLDER: confirm security@ mailbox exists before launch]Three questions cautious investors ask
Ready to see the whole picture?
Connect your first account free — no card required.