Security

Why would you trust this with your money?

Fair question. You do not have to hand over a key at all, and where you do, this page says what happens to it. It also says what is not finished yet, because a security page that only boasts is not worth reading.

What is true today

The parts that are built and working

Read-only

Worthly reads. Its code contains no call that places an order, withdraws or moves money anywhere.

The key permissions are set on the platform when you create the key, so we ask for read-only keys and say how to make one. If a read-only key ever leaked, what is at stake is privacy, not your funds.

Keys are encrypted

Exchange credentials are encrypted before they are written to the database, with authenticated encryption. The master key is not stored in the database; it lives in the server environment.

Each time a stored credential is decrypted, the event is written to an audit log. Database backups are encrypted too, and your data export never contains your keys.

Your positions are yours

They are never shared, sold or released, not even anonymised. There are no ads and no ad trackers on the product.

Worthly is closed source and copyrighted. That means you cannot audit the code yourself, so the trust has to rest on what is written here, on how the product is built, and on the person behind it.

Your account

Passwords need at least 8 characters, an uppercase letter and a digit, and are stored only as a slow argon2 hash. An account exists only after you enter a 6-digit code mailed to your address (valid 15 minutes, 5 tries). You must verify your email before connecting a platform.

Sign-in attempts are rate-limited per account, and the login does not reveal whether an email is registered.

Sessions

Access tokens last 60 minutes. A longer-lived refresh token (30 days) is replaced every time it is used, and signing out revokes it. Resetting your password ends your other sessions, and signing out clears the offline copy of your data from the device.

Two-factor sign-in

Optional, and worth switching on. Any authenticator app works (time-based one-time codes). Turning it on or off asks for your password again. You get 10 recovery codes, shown once and stored only as hashes.

Your data, your exit

You can download everything of yours as a file, and delete your account, from inside the app. Deletion needs a 6-digit code mailed to you, then removes your account and the data attached to it.

One thing is kept: a short audit trail saying that some credential was decrypted at some time. After deletion it is no longer linked to anyone, and it ages out after 180 days.

What is not true yet

The roadmap, stated plainly

Worthly has not launched publicly. Several protections are built but can only be switched on once it has a real domain and server. None of them is claimed as live below.

ProtectionWhere it stands
HTTPS and HSTSHSTS is built and turns on in production. It needs a domain with HTTPS first.
Content Security PolicyRunning in report-only mode. Framing is already blocked, but the policy is not enforced until it can be tested against the real domain.
PasskeysNot built. They are tied to a domain, so they wait for one. Until then, the authenticator-app code is the second factor.
Outgoing emailSign-up, password reset and deletion codes are sent by email, and mail delivery is configured together with the server.
Session storageSign-in tokens are kept in the browser storage, not in locked-down cookies. That is the usual single-page-app trade-off and is only fully mitigated by an enforced CSP.
Off-site backupsBackups are encrypted and verified to restore, but their copy still sits on the same machine. Off-site means off-site, and that comes with the server.
Master-key rotationThe key that protects stored credentials cannot yet be rotated. It is backed up, but a rotation path is not built.
Lost phone and recovery codesIf you lose both your authenticator and your recovery codes, recovery is a manual step by the author. Keep the codes somewhere safe.

Found something that looks wrong? Say so in the Discord or in a message to the author. It will be read by a person.

Your money. Your call.

Start with manual entry if you like, add a read-only key later, or never.