> ## Documentation Index
> Fetch the complete documentation index at: https://bigbrainape.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Security on Big Brain Ape: Protecting Your Account

> Learn about Big Brain Ape's security features including 2FA, API key scoping, non-custodial wallet design, and best practices to protect your account.

Big Brain Ape is built with security at every layer. Whether you're connecting a wallet, running automated trading scripts, or simply monitoring your portfolio, your account is protected by a combination of non-custodial architecture, two-factor authentication, scoped API access, and real-time security alerts. Understanding these features — and using them well — is the single most effective way to keep your assets safe.

## Non-custodial architecture

Big Brain Ape never stores your private keys, seed phrases, or wallet credentials on its servers. When you connect a wallet to the platform, all transactions are signed locally by your wallet before being broadcast to the network. This means that even if Big Brain Ape's infrastructure were ever compromised, your funds would remain secure — there is nothing to steal. You remain in full control of your assets at all times.

<Warning>
  Never enter your seed phrase or private keys into any website, app, or form — including anything that claims to be Big Brain Ape. Our platform will never ask for them.
</Warning>

## Account security features

These built-in tools work together to keep your account and trading activity protected.

<CardGroup cols={2}>
  <Card title="Two-Factor Authentication" icon="shield-halved" href="/security/two-factor-auth">
    Add a second layer of login protection using a TOTP app such as Google Authenticator or Authy. 2FA is required to create or delete API keys.
  </Card>

  <Card title="API Key Scoping" icon="key" href="/security/api-keys">
    Generate API keys with only the permissions your integrations need. Restrict keys by IP address and rotate them on a regular schedule.
  </Card>

  <Card title="Session Management" icon="clock-rotate-left">
    View and revoke all active sessions from the Security settings page. Any session can be terminated instantly if you don't recognise it.
  </Card>

  <Card title="Activity Log" icon="list-check">
    Every login, API key event, and trade action is recorded in your activity log with timestamps and IP addresses so you can spot anything unusual.
  </Card>
</CardGroup>

## Security checklist

Work through this list to make sure your account is locked down before you start trading.

* ✅ **Enable two-factor authentication.** Go to Settings → Security and turn on 2FA with an authenticator app. Store your backup codes somewhere safe and offline.
* ✅ **Use a strong, unique password.** Your Big Brain Ape password should be at least 16 characters long and used nowhere else. A password manager makes this easy.
* ✅ **Review connected apps and sessions.** Open Settings → Security and revoke any sessions or third-party connections you don't recognise.
* ✅ **Scope your API keys tightly.** Only grant the permissions each key actually needs. Add an IP allowlist whenever your script runs from a fixed address.
* ✅ **Rotate API keys regularly.** Create a replacement key, update your integration, then revoke the old key. Aim to rotate at least every 90 days.
* ✅ **Keep your recovery email secure.** The email address on your account is a recovery path — protect it with its own strong password and 2FA.

## Security alerts

Big Brain Ape automatically sends you an email notification when any of the following events occur on your account:

* A new login is detected, including the device type and IP address
* An API key is created or revoked
* A trade above your configured size threshold is placed
* A password change or 2FA setting is modified

If you receive an alert for an action you didn't take, go to Settings → Security immediately, revoke all active sessions, and contact support.

<Warning>
  Never share your API keys or seed phrase with anyone — including Big Brain Ape support staff. Our team will never ask you for either of these.
</Warning>

## Explore security settings

<CardGroup cols={2}>
  <Card title="Two-Factor Auth" icon="mobile-screen" href="/security/two-factor-auth">
    Set up TOTP-based two-factor authentication to protect your logins and sensitive account actions.
  </Card>

  <Card title="API Keys" icon="key" href="/security/api-keys">
    Create scoped API keys, configure IP restrictions, and learn how to rotate and revoke them safely.
  </Card>
</CardGroup>
