> ## Documentation Index
> Fetch the complete documentation index at: https://readme.amana-dev.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Considerations

> Protect credentials, client data, and financially sensitive operations in your integration.

Design security around both confidential partner access and the client-facing workflows in your application. Confirm endpoint-specific requirements before implementing authentication.

## Protect Credentials

* Keep confidential partner credentials on your backend, not in web or mobile application bundles.
* Store secrets using a secret-management mechanism and restrict who can access them.
* Confirm credential expiry, rotation, and revocation procedures with Amana.
* Never include credentials in documentation examples, screenshots, logs, or support tickets.

## Enforce Account Boundaries

Verify which client and trading account each request is authorized to act on. Do not rely on a client-supplied account identifier alone. Use the agreed access model and validate isolation between users and accounts.

## Protect Client Data

Use HTTPS for API requests. Limit the personal and financial data your application stores or logs, and restrict access according to the responsibilities agreed for your partnership.

## Treat Financial Actions Carefully

Make the environment and selected account explicit in your application. Require deliberate client actions for financially sensitive requests. Confirm the supported way to reconcile uncertain outcomes before retrying orders or funding operations.

## Prepare for Incidents

Agree how to report suspected credential exposure, unauthorized access, and trading or funding discrepancies. Document how your team will contain an incident, revoke affected access, and preserve relevant evidence without exposing client data.

Review the [go-live checklist](/integration-guides/go-live) before launch.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.