TRUST CENTER

Trust, data boundaries, and capital controls for serious Polymarket workflows.

Temirin is built around a simple operating promise: keep sensitive workflows gated, keep source and price context inspectable, avoid unnecessary secrets, and preserve an audit trail for the decisions that matter.

SECURITY POSTURE

Clear boundaries for public data, scoped credentials, and controlled live orders.

The trust model separates read-only public-wallet context from live-order authorization, shows which encrypted credentials are stored, fail-closes transmission until every gate passes, and keeps signing, custody, provider outcomes, and final user authorization outside Temirin's control.

Account access

Temirin workspaces are locked behind verified passwordless access. The Command Center, billing controls, sources, alerts, and team settings are available only after session verification.

Read-only public-wallet boundary

A saved public wallet is read-only portfolio, position, PnL, history, and risk context. Saving or proving that address does not grant trading authorization.

Credential handling

Supported source, destination, and Polymarket CLOB L2 credentials use encrypted server-side storage, scoped access checks, explicit revocation, safe metadata-only responses, and no secret echoing back to the browser. A CLOB API credential is separate from a wallet private key and cannot sign a wallet order.

Controlled live-order boundary

Controlled live-order transmission is a separate, explicit workflow for eligible accounts, jurisdictions, and deployments. It requires encrypted scoped CLOB L2 credentials, a provider-required wallet-signed order, current legal and risk acknowledgements, pre-trade confirmation, and a final fail-closed eligibility check.

Venue and custody boundary

TEMIRIN is non-custodial workflow software, not a broker or autonomous trading system. It never asks for a private key or seed phrase, cannot sign wallet transactions, does not move or custody wallet funds, and does not guarantee order acceptance, matching, fills, cancellation, settlement, resolution, or outcomes.

Fail-closed execution gates

Live transmission stays disabled unless the current legal, jurisdiction, wallet proof, scoped credential, policy, risk, adapter, durable ledger, and deployment gates are all ready. The dashboard rechecks eligibility immediately before sending a user-confirmed signed order.

Source transparency

RSS, HTTPS pages, market data, and provider-configured Telegram or X items are stored as inspectable evidence. Opportunity records keep evidence context, trigger price, current price, confidence, and blocked reasons visible.

Audit trails

Authentication, connector and credential changes, billing events, source ingestion, decisions, legal and policy acknowledgements, support and team actions, paper orders, live transmission, provider responses, fills, reconciliation, sync, and cancellation actions are recorded for operational review.

Paper and live-order controls

Paper orders remain non-transmitting records with workflow and risk checks. Controlled live orders add exact-order economics review, provider-required signed authorization, two explicit confirmations, role checks, risk and exposure limits, lifecycle reconciliation, per-order cancellation, and a kill-switch cancel-all path.

Data controls

Authenticated users can export workspace data and request deletion of account-controlled records, subject to legal, billing, security, and audit retention needs.

Billing boundary

Payment providers handle hosted checkout, payment collection, and card data. Temirin stores subscription, entitlement, invoice, and provider-reference records without storing raw card numbers or CVV data.