Permissions that stay disabled

Order placement, trading, internal transfers, address management and withdrawals are outside the portfolio workflow. Do not connect a credential when the provider cannot separate those permissions from reads.

Encrypted storage is only one layer

Credentials are encrypted at rest and decrypted only at the connector boundary, but users should still restrict permissions, use provider IP controls when practical and rotate keys after suspected exposure.

Deletion and revocation are different

Removing a ChainsFlow connection deletes the service copy and its stored portfolio data. The original credential must still be revoked in the exchange security settings.