# Is my exchange access secure?

**Your coins stay on Binance.** The bot places Spot orders under your plan. The API key has withdrawals off, so it cannot cash you out.

<Lock
seals={[
{ title: 'Key on your box', detail: 'This IP only' },
{ title: 'Trade only', detail: 'Spot orders' },
{ title: 'Withdraw', detail: 'Refused' },
]}
caption="The bot can trade. It cannot cash you out."
/>

### Trading access only — no cash-out key

For live trading, bud checks your Binance API key before it will use it.

- Spot trading must be on (so the bot can buy and sell)
- **Withdrawals must be off** — if a key can send money off Binance, bud refuses it

The key can place Spot orders. Withdrawals stay off.

### Keys stay on your cloud box

Your Binance secret lives on your private cloud box, in locked-down files. The iPhone app and the web app talk to CryptoBud with a login token.

That cloud box is yours alone.

### Locked to your trading IP

Binance requires an IP when you turn on trading permission. We email you that IP for your CryptoBud cloud box. You paste it when you create the key, then put the key in the [iPhone app](/get) or the [web app](/pwa).

So the key only works from your box.

Keep the usual exchange hygiene too: 2FA on the account, and rotate the key if you ever worry it leaked.

### What the key can do

- Buy and sell Spot under the plan you set, including while you sleep, plus reports and alerts
- Withdrawals stay off. Bud refuses a key that can send coins off Binance

Paper mode needs no keys at all — practice first. Live mode uses real money on your Spot balance. [How to start live trading →](/help/how-do-i-start-live-trading)

Overlays like [Cryptohopper](/compare/cryptohopper), [Bitsgap](/compare/bitsgap), [3Commas](/compare/3commas), and [Stoic AI](/compare/stoic-ai) keep coins on the exchange too — and store the API key on their cloud. Bud keeps the key on your box. [How we compare →](/compare)