Trust / Connections
Account Linking
Connect the least authority possible. Zavit's public launch uses linked accounts for read-only portfolio intelligence, not order placement or withdrawals.
Last updated July 19, 2026 · Effective July 19, 2026
1. Read-only launch scope
A supported connection may retrieve venue account metadata, balances, positions, orders, fills, and related portfolio records. Connecting an account does not enable production execution. Zavit does not request or support withdrawal authority.
2. Credential handling
Use a dedicated read-only API credential where the venue supports one. Private credential material is encrypted before storage and is not displayed again. Zavit may retain non-secret credential metadata, connection status, timestamps, and audit records needed to operate and protect the connection.
3. Public-wallet connections
A public wallet address and its on-chain activity may already be publicly visible. Treat the address as account-linked information even when no private key is provided. Zavit does not need a seed phrase or wallet private key for a read-only public-address connection; never submit either.
4. Disconnect and revoke
Disconnecting stops Zavit from using the stored connection but may not revoke the credential at the venue. For complete revocation, delete or disable the API key in the venue's own security settings and review recent venue activity. If compromise is suspected, revoke at the venue first, then disconnect in Zavit.
5. Sync and provider risk
Venue APIs, rate limits, sessions, and networks can fail. Zavit data may lag the venue and should not be the only way you monitor an account. Keep venue-native access and security controls available.
6. Your responsibilities
Connect only an account you are authorized and eligible to use. Safeguard credentials, follow provider terms, review permissions, and report or revoke unexpected activity promptly. Do not share a linked Zavit session with another person.