> For the complete documentation index, see [llms.txt](https://upscalp.gitbook.io/upscalp-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://upscalp.gitbook.io/upscalp-docs/trust-and-safety/upscalp-security-and-account-protection.md).

# Protect Your UpScalp and Exchange Accounts

**Last reviewed:** 2026-05-23.

Most support and security problems start with a bad link, a fake support DM, or weak account protection. Use this checklist before linking UpScalp to any trading activity.

Check API-key safety, exchange credentials, withdrawal permissions, fake support messages, and any request for secrets before acting.

## Start from official links

1. Open links from [Official Links and Channels](https://upscalp.gitbook.io/upscalp-docs/reference/upscalp-official-links).
2. Compare Telegram usernames character by character.
3. Treat unsolicited support DMs as suspicious.
4. Do not act on urgency messages asking for funds, wallet access, or secrets.

## Secure Telegram and exchange accounts

1. Use unique passwords stored in a password manager.
2. Enable two-factor authentication where available.
3. Review active sessions.
4. Log out unknown devices.
5. Keep recovery email and phone access secure.

## Keep secrets out of chat

Never share:

1. Seed phrases.
2. Private keys.
3. Exchange passwords.
4. Exchange API secrets.
5. Account recovery codes.

UpScalp support will never ask for seed phrases, private keys, exchange passwords, exchange API secrets, or account recovery codes.

## API keys and exchange permissions

Lite and Premium do not require you to create exchange API keys.

If you are approved for a Private Beta API setup, follow only the official approved setup. Stop and contact support if any instruction asks you to:

1. Enable withdrawal permissions.
2. Send API keys through Telegram, email, chat, or support messages.
3. Paste exchange credentials into an unofficial form.
4. Use a different Telegram bot or support account.

## Before any approved API setup

Only continue with API setup when all checks pass.

| Check        | Required condition                                                                           |
| ------------ | -------------------------------------------------------------------------------------------- |
| Approval     | You have explicit Private Beta approval through the official route.                          |
| Instructions | The setup instructions come from the approved setup, not a public chat or DM.                |
| Permissions  | Withdrawal permission is off. Any requested permission is limited to the approved setup.     |
| Storage      | You are not asked to send API keys or secrets through chat, email, or screenshots.           |
| Doubt        | If anything differs from the approved setup, you stop and contact support before continuing. |

## If compromise is suspected

1. Stop trading actions.
2. Revoke suspicious sessions and permissions.
3. Change passwords from a clean device.
4. Rotate two-factor authentication if needed.
5. Record a UTC timeline.
6. Contact support with evidence that does not expose secrets.

## Report a security issue

If you have found a bug, vulnerability, or fraud attempt that affects other UpScalp users, please report it privately first.

Email `upscalpbot@gmail.com` with `[SECURITY]` in the subject line. Include:

1. What you found.
2. The exact steps to reproduce, if you have them.
3. The route, link, bot, or page where you saw it.
4. The UTC time you observed it.
5. Whether you believe other users may already be affected.

Do not include private keys, API secrets, account credentials, or another user's personal data in the report. A screenshot with sensitive parts blurred is fine.

Hold off on public posts (including in Telegram groups) until support has had a chance to respond, so the issue is not amplified while it is being addressed.

## Related

1. [Official Links and Channels](https://upscalp.gitbook.io/upscalp-docs/reference/upscalp-official-links)
2. [Contact Support](https://upscalp.gitbook.io/upscalp-docs/troubleshooting/upscalp-contact-support)
3. [Legal and Trading Risk Notice](https://upscalp.gitbook.io/upscalp-docs/trust-and-safety/upscalp-legal-and-risk-notice)
4. [What UpScalp Does and Does Not Automate](https://upscalp.gitbook.io/upscalp-docs/trading-principles/upscalp-what-upscalp-does-and-does-not-automate)
