Funds stay at Kalshi
We do not hold customer funds or operate a pooled trading account. The product connects to the Kalshi account you control.
Bot for Kalshi is non-custodial software. Your money remains at Kalshi, you define the rules and limits, and live orders require your explicit activation.
We do not hold customer funds or operate a pooled trading account. The product connects to the Kalshi account you control.
Kalshi private keys are encrypted at rest with per-user envelope encryption. You can remove a stored key in Settings or revoke it directly at Kalshi.
A draft or paper test cannot place a live order. Paper uses your Kalshi API key to read market data; placing live orders is a separate, explicit permission you give when you turn a bot on with real money.
Position caps, loss limits and order conditions are part of the strategy you inspect. Activity receipts show what ran and why.
Session cookies are HTTP-only and SameSite, with idle and absolute expiration. Production cookies are sent only over HTTPS.
Responses use a content security policy, clickjacking protection, strict transport security in production, and restrictive browser permissions.
State-changing browser requests are checked against their origin, and sensitive API paths are authenticated and rate limited.
You can remove your account data and stored credentials from account settings. Our Privacy Policy explains collection and retention.
Frontier models help draft and reason about strategies in the builder. You review the resulting rules and control live activation. The hosted engine evaluates supported rules under your configured permissions and limits. Model output can contain mistakes; inspect it and paper-test before using live funds.
For account access, billing or bot help, use Support. Current service health is available on the Status page.
This is a plain-language description of controls currently implemented in the product, not a claim that any internet service can eliminate every risk. Material customer-facing changes are recorded in the public changelog.