> For the complete documentation index, see [llms.txt](https://listed-exchange.gitbook.io/listed/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://listed-exchange.gitbook.io/listed/how-it-works/security.md).

# Security & custody

## Non-custodial by construction

LISTED never holds your funds. There is no deposit, no LISTED-controlled wallet, no account. Every action is a transaction your wallet signs:

* **Swaps** settle straight from your wallet to the venue's router. LISTED builds the calldata; you sign it.
* **Limit orders** are an off-chain signature that rests in KyberSwap's book. Your tokens stay put until a taker fills you.

If LISTED's front end went offline tomorrow, your funds and your on-chain positions would be unaffected.

## Approvals

LISTED asks for approvals per-trade, at execution time — never a blanket approval on connect.

* Default approvals are **exact-amount**. You can opt into infinite approvals per token in the swap settings if you trade it often.
* Where a venue uses **Permit2**, the approval is a signature, not a standing allowance to LISTED.
* Approvals go to the **venue's router**, not to LISTED.

## Execution safety

* Every built swap carries its own **on-chain minimum-output** at your slippage. If the transaction can't deliver that, it reverts — you don't lose the trade to a bad fill.
* LISTED **simulates** the settlement transaction server-side before handing it to you, and falls through to the next venue if it would revert.
* A quote that's gone stale, or a fresh build that re-prices materially worse, **stops** rather than submitting.
* Slippage above 25% requires a confirmation. Adverse price impact above 10% requires an acknowledgement.

## Frontend hardening

* Strict **Content-Security-Policy**: `default-src 'self'`, `frame-ancestors 'none'`, `object-src 'none'`, no third-party script origins beyond what's required for the wallet and the TradingView chart frame.
* `X-Content-Type-Options: nosniff`, `X-Frame-Options: DENY`, `Referrer-Policy: strict-origin-when-cross-origin`, a restrictive `Permissions-Policy`.

## What LISTED can't protect you from

* **The issuer of a tokenized stock.** Redemption, dividends, and tracking are the issuer's terms, not LISTED's.
* **A compromised venue or pool.** LISTED routes to third-party contracts; a bug or exploit in one of them is outside LISTED's control (though the min-output floor and pre-simulation limit the blast radius).
* **Your own key.** LISTED has no recovery, because it has no account.
* **Phishing.** Only ever use [listed.exchange](https://listed.exchange). LISTED will never DM you or ask for a seed phrase.
