Permissions that stay disabled
Order placement, trading, internal transfers, address management and withdrawals are outside the portfolio workflow. Do not connect a credential when the provider cannot separate those permissions from reads.
Encrypted storage is only one layer
Credentials are encrypted at rest and decrypted only at the connector boundary, but users should still restrict permissions, use provider IP controls when practical and rotate keys after suspected exposure.
Deletion and revocation are different
Removing a ChainsFlow connection deletes the service copy and its stored portfolio data. The original credential must still be revoked in the exchange security settings.