Disclosure and boundaries
Security
Report a suspected vulnerability privately. This page states the controls visible in the current product and deliberately makes no certification, audit, uptime, or response-time claim.
Last reviewed 2026-09-05
Report a vulnerability
Email security@worldeventtrading.com with “Security” in the subject. Include the affected URL or component, reproduction steps, impact, and a safe way to validate the finding. Do not include another person's personal data or a live secret unless necessary.
Credential boundary
- The seven public MCP research tools require no account credential and are read-only.
- Account API keys are shown once when created; only a one-way key hash is stored for later verification.
- API-key scopes are selected at creation and are not widened in place. Create a new key when different scopes are needed.
- Keys belong in an authorization header or secure secret store, never in a prompt, URL, source file, screenshot, or support post.
- Revoking a key prevents later use; it does not undo account actions already completed with it.
MCP and execution boundary
The unauthenticated MCP surface exposes exactly seven read-only research tools. A valid, scoped W.E.T. API key can append tools over the holder's own watchlists, saved views, alerts, and scanners; documented account tools can create or delete W.E.T. account state. No public or account tool can place, route, cancel, simulate, or custody an order. W.E.T. is not an exchange, broker, FCM, or DCM.
What we are not claiming
W.E.T. does not currently publish a SOC 2, ISO 27001, penetration-test, coordinated safe-harbor, uptime SLA, or guaranteed remediation window. A hosting provider's certification is not presented as W.E.T.'s certification. If that posture changes, this page will be dated and updated.