01Exchange API authority
Inventory read/trade permissions, prove withdrawals are disabled for the scoped bot key, bind access to approved network origins where supported, separate bot capital from the master account, and define key rotation/revocation ownership.
02Secret & runtime boundary
Check how API credentials are provisioned, isolated and redacted. Public scope preparation never accepts API keys, secrets, private keys or wallet seeds.
03Pre-trade decision gates
Map which evidence must be fresh before an order may be proposed: instrument, account, size, market state, liquidity/slippage controls, pair age where relevant, frequency limits and loss/drawdown controls. Thresholds are system-specific, not universal BitEvo defaults.
04Order & effect confirmation
Separate intent, exchange acknowledgement, open order, partial fill, fill, cancel and resulting position. A successful API response is not treated as proof that the intended market effect occurred.
05Retry, interruption & recovery
Test duplicate prevention, stale-state handling, cancel/reconcile paths, kill/hold behavior and restart from a known state. Flattening or key revocation is tested only when separately authorized in a safe environment.
06Authority change control
Identify who may expand symbols, accounts, order types, leverage, sizing, execution venues or credential permissions, and require evidence-bound owner approval before authority expands.