Home Product Pricing Security Proof FAQ Support Start on Telegram
Security

Built with trust, restraint, and operational safeguards

Designed to be useful in production, not just impressive in screenshots.

Exchange connection

Structured onboarding, permission-aware guidance, and a supported exchange path. The bot explains exactly which API permissions are needed and why.

GoodBoyTrader cannot withdraw your funds. Trade-only API permissions mean the bot can open and close positions on your behalf, but it has no ability to transfer, withdraw, or move any funds out of your exchange account. Your money stays on your exchange at all times.

📋

Clear onboarding flow

Guided API setup inside Telegram. Step-by-step instructions so you know what to configure and where.

🔗

Supported exchange path

Bitget USDT-M Futures — tested and hardened. The bot is built around a single, well-understood integration.

🔐

Permission-aware guidance

The bot explains exactly which API permissions are needed and why. No broad access requests without context.

Risk-first system behavior

🛑

Stop-loss and trade control flows

Hard stop-loss, custom TP/SL, and strategy-aware exits. You stay in control of risk parameters.

📊

Capital and position constraints by tier

Tier-based limits on positions, size, and alerts. No unbounded exposure. Manual trades, alert trades, and auto trades are tracked separately with clear attribution for every action.

🛡️

Protection checks before every action

Balance gates, position limits, and quality filters run before any trade is placed. Alert Mode requires your approval; Full Auto runs only when you explicitly enable it.

📈

Trailing stops and strategy-aware exits

Built-in exit logic that respects strategy design. No blind time-stops or arbitrary cutoffs.

Production posture

Real production setup — not a hobby project. Infrastructure is hardened for reliability and observability.

Cloudflare DDoS/WAF
Sentry error monitoring
Uptime monitoring
Staging environment
Webhook production deployment
HMAC webhook validation

How credentials are handled

API keys are encrypted at rest using Fernet symmetric encryption. They are never stored in plaintext, never logged, and never committed to version control. Per-exchange key isolation means switching exchanges does not expose other credentials.

1

Encrypted at rest

Stored only in encrypted form.

2

Decrypted only in memory

Resolved only for the live action that needs them.

3

Never stored in plaintext

Not logged, not committed, not exposed across exchanges.

What GoodBoyTrader is not

It is not a guarantee of returns. It is not a substitute for understanding risk. It is not a promise that historical results will repeat. Trading cryptocurrency futures involves significant risk of loss. Use only funds you can afford to lose.

GoodBoyTrader cannot withdraw your funds. The API permissions required are trade-only. The bot can open and close positions on your behalf, but it has no ability to transfer, withdraw, or move any funds out of your exchange account. Your money stays on your exchange at all times.

See the product in action

Trade-only API Encrypted at rest Cannot withdraw funds