> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neurobro.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# LEGAL TODO

# Legal TODO

Tracking legal elements/pages that need to be added, updated, or completed.
Items marked **⚠ COUNSEL** require a legal/business decision before publishing.
Items checked `[x]` were applied to `terms-of-use.mdx` (v0.7) / `privacy-policy.mdx` (v0.8); latest pass 2026-05-22.
Analytics: PostHog replaced with self-hosted, open-source Matomo (in-house); Google Analytics and Sentry retained.

## Affiliate / Exchange Disclosure

* [x] **Affiliate Disclosure page** — `legal/affiliate-disclosure.mdx` finalized (May 22, 2026): removed the draft TODO, discloses commission + geo-gating in FTC-clear wording, cross-links to ToS/PP, contact set to info\@. Per owner request the page is kept generic — it does NOT name the exchanges or state live scope; those specifics live in ToS §5.3. Counsel sign-off still recommended.
* [x] **Exchange naming** — handled in ToS §5.3 and PP §6 (affiliate page intentionally defers to them).
* [ ] **Affiliate page per-exchange policy links** — optionally add direct links to each exchange's terms/privacy/AML on the affiliate page (currently cross-linked via ToS §3.5 / PP §6).
* [x] **Name all six exchanges** — Binance, OKX, Bybit, KuCoin, Indodax, Tokocrypto disclosed individually in ToS §3 and PP §6 (each a separate legal entity / independent data controller).
* [ ] **Affiliate links live only for Bybit & KuCoin** — business/counsel to confirm scope before launch (no longer stated on the affiliate page). Binance/OKX/Indodax/Tokocrypto links currently disabled.
* [ ] **⚠ COUNSEL — placeholder benefit figures** — do NOT publish placeholder promo figures (e.g. "-20% fees", "\$10,000 rewards"); replace with contractually accurate terms or risk advertising-law exposure.
* [x] **Update Terms of Use affiliate section** — ToS §5.3 (formerly §4.3) updated: names the six exchanges, discloses commission, adds geo-gating; uses "affiliate" terminology throughout.

## Exchange Legal-Document Links

* [x] **Embed exchange legal links** — referenced in ToS §3.5 (exchange Terms) and PP §6 (exchange Privacy Policies). Links verified working on 2026-05-19; re-check before publishing. Note: only Terms (ToS) and Privacy (PP) are embedded; AML/compliance links are not embedded in the user-facing docs (most exchanges have no standalone AML URL — see notes below).

| Exchange   | Document                           | URL                                                                                                                                                                                        |
| ---------- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Binance    | Terms of Use                       | [https://www.binance.com/en/terms](https://www.binance.com/en/terms)                                                                                                                       |
| Binance    | Privacy Portal                     | [https://www.binance.com/en/about-legal/privacy-portal](https://www.binance.com/en/about-legal/privacy-portal)                                                                             |
| Binance    | Compliance / AML (Binance.US)      | [https://www.binance.us/compliance](https://www.binance.us/compliance)                                                                                                                     |
| OKX        | Terms of Service                   | [https://www.okx.com/help/terms-of-service](https://www.okx.com/help/terms-of-service)                                                                                                     |
| OKX        | Privacy Notice                     | [https://www.okx.com/help/privacy-policy-statement](https://www.okx.com/help/privacy-policy-statement)                                                                                     |
| OKX        | Risk & Compliance Disclosure (AML) | [https://www.okx.com/help/risk-compliance-disclosure](https://www.okx.com/help/risk-compliance-disclosure)                                                                                 |
| Bybit      | Terms of Service                   | [https://www.bybit.com/en/legal/terms-of-service](https://www.bybit.com/en/legal/terms-of-service)                                                                                         |
| Bybit      | Privacy Policy                     | [https://www.bybit.com/en/legal/policies-and-rules/privacy-policy](https://www.bybit.com/en/legal/policies-and-rules/privacy-policy)                                                       |
| Bybit      | User Protection & Compliance (AML) | [https://www.bybit.com/en/promo/global/user-protection](https://www.bybit.com/en/promo/global/user-protection)                                                                             |
| KuCoin     | Terms of Use                       | [https://www.kucoin.com/legal/terms-of-use](https://www.kucoin.com/legal/terms-of-use)                                                                                                     |
| KuCoin     | Privacy Policy                     | [https://www.kucoin.com/legal/privacy-policy](https://www.kucoin.com/legal/privacy-policy)                                                                                                 |
| Indodax    | Terms and Conditions               | [https://help.indodax.com/hc/en-us/articles/4416650994585-Terms-and-Conditions](https://help.indodax.com/hc/en-us/articles/4416650994585-Terms-and-Conditions)                             |
| Indodax    | Privacy Notice                     | [https://help.indodax.com/hc/en-us/articles/19751527469721-Privacy-Notice](https://help.indodax.com/hc/en-us/articles/19751527469721-Privacy-Notice)                                       |
| Tokocrypto | User Agreement (Terms of Service)  | [https://support.tokocrypto.com/hc/en-us/articles/360004044971-Tokocrypto-User-Agreement](https://support.tokocrypto.com/hc/en-us/articles/360004044971-Tokocrypto-User-Agreement)         |
| Tokocrypto | Privacy Policy                     | [https://support.tokocrypto.com/hc/en-us/articles/21694168727565-Privacy-Policy](https://support.tokocrypto.com/hc/en-us/articles/21694168727565-Privacy-Policy)                           |
| Tokocrypto | AML/CFT Policy                     | [https://support.tokocrypto.com/hc/en-us/articles/4812240530317-AML-CFT-Policy-in-Tokocrypto](https://support.tokocrypto.com/hc/en-us/articles/4812240530317-AML-CFT-Policy-in-Tokocrypto) |

Notes on gaps (no standalone, verifiable AML-policy URL exists):

* **Binance** — no global standalone AML page; AML is inside the Terms. The dedicated compliance page exists only on the US entity. The global Privacy Notice is jurisdiction-specific, so the Privacy Portal is the canonical entry point.
* **Bybit** — no standalone canonical AML document; the User Protection & Compliance page is the closest official page. AML obligations are also embedded in the Terms.
* **KuCoin** — no standalone public AML/CTF URL; AML/CTF content is incorporated into the Terms of Use and Privacy Policy.
* **Indodax** — no standalone AML page; AML/CFT is covered within the Terms and Privacy Notice. Help-center pages are bot-protected (HTTP 403 to automated browsers) but confirmed published.
* **Tokocrypto** — all three documents (incl. a dedicated AML/CFT policy) confirmed via the help-center API.

## Privacy Policy updates

* [x] **Disclose exchange/portfolio financial data collected** — PP §2 now covers credentials, balances/holdings, full trade/order/transfer/ledger history, open positions & PnL, net-worth history, public wallet addresses and on-chain transaction IDs, with a sensitivity warning.
* [x] **Sub-processor list** — PP §6 "Third Parties and Sub-Processors" lists the 6 exchanges, AWS, Alchemy, CoinGecko, the LLM providers, and the existing analytics/payment processors.
* [x] **AI provider transparency** — PP §7 names the LLM providers (OpenAI, Anthropic, Google, Groq, xAI, DeepSeek), discloses that portfolio data is sent as context, and notes routing varies by tier/backend.
* [ ] **⚠ COUNSEL — DeepSeek routing** — decided (disclosed in PP §7) & applied; counsel still to confirm acceptability of China-based routing of financial data for EU/UK users.
* [ ] **⚠ COUNSEL — full-history ingestion** — lawful basis stated as Contract in PP §2 & applied; counsel to confirm (GDPR Art. 6).
* [ ] **⚠ COUNSEL — retention period** — event-based retention adopted & applied in PP §4 (retained until disconnect/account deletion); counsel to confirm against GDPR Art. 5(1)(e) storage limitation.
* [x] **Document deletion mechanics** — PP §5 "Erase" extended: disconnect hard-deletes that exchange's data; account deletion cascades to all portfolio data. Cross-references `legal/account-deletion.mdx`.
* [x] **Net-worth snapshot retention** — disclosed in PP §2 and §4 (retained for the life of the account, deleted on account deletion).
* [x] **International data transfer disclosure** — PP §8 "Third-Party Processing" updated for the new sub-processors and the EU/US/Singapore/China jurisdictions.
* [x] **Per-exchange data-coverage differences** — noted in PP §2 (some connected exchanges provide spot-only data).

## Terms of Service / Terms of Use updates

* [x] **Read-only API key / non-custodial disclaimer** — ToS §3 "Read-Only Exchange Connections" added: read-only keys only, no order-execution/trading/withdrawal capability.
* [x] **No financial advice for AI portfolio commentary** — ToS §4.4 added covering AI-generated commentary on the user's connected portfolio.
* [x] **NFA / DYOR disclaimer** — extended in ToS §4 (informational only, not advice, DYOR, consult professionals).
* [x] **Jurisdiction / eligibility clause** — ToS §5.3 documents affiliate-link geo-gating (sanctions: Iran/North Korea/Cuba/Syria; UK FCA regime; per-exchange blocks) and clarifies it affects affiliate-link display only.

## Critical review findings (2026-05-22) — counsel / engineering required

From the four-agent legal review of PR #77. These are NOT pure wording fixes — each needs a legal or engineering decision before launch.

* [ ] **⚠ COUNSEL — EU & UK Art. 27 representatives (MISSING)** — a US-only controller serving/monitoring EU/UK users must appoint, and disclose, both an EU and a UK representative. Neither is named. Standalone GDPR breach.
* [ ] **⚠ COUNSEL — DeepSeek/China transfer mechanism** — bare "SCCs where applicable" is likely indefensible for China (no adequacy; Schrems II TIA; live DPA bans on DeepSeek in Italy/Germany). Exclude DeepSeek for EU/UK users or hold a documented TIA. (Strengthens the existing DeepSeek item.)
* [ ] **⚠ COUNSEL — UK FCA core-service exposure** — ToS §5.3 states geo-gating does not restrict the core Services, but promoting \$BRO + AI Alpha to UK consumers may itself be a regulated financial promotion (criminal exposure) regardless of affiliate links. Decide: geo-block core promotional/AI Alpha/token surface for the UK, or obtain a lawful route. ToS currently understates this.
* [ ] **⚠ COUNSEL — consumer arbitration clause** — ToS §13 mandatory Delaware arbitration is likely unenforceable against EU/UK consumers (UCTD/Brussels Ia) and omits a US class-action waiver. Add a class-action waiver + EU/UK/Canada consumer carve-out.
* [ ] **⚠ COUNSEL — CCPA/CPRA California section** — add notice-at-collection, California consumer rights, and the SPI right-to-limit (exchange API credentials = Sensitive Personal Information under CPRA). Currently only one line.
* [ ] **⚠ COUNSEL — Art. 22 profiling/ADM disclosure** — disclose the existence, logic, and significance of AI profiling of user portfolios (AI Alpha, portfolio commentary).
* [ ] **⚠ COUNSEL — lawful-basis reconciliation** — ToS §9.2 grants a "perpetual license … for training" while PP §7 says LLM data is used "solely to generate the response you requested." Reconcile, and give training/improvement its own basis (consent or LI + balancing test).
* [ ] **⚠ COUNSEL — ePrivacy cookie/analytics consent** — GA/Matomo/Sentry client SDKs require prior opt-in consent in EU/UK; PP labels analytics "legitimate interest" in places. Confirm the cookie banner is prior, granular, opt-in and align the stated basis.
* [ ] **⚠ COUNSEL — MSB/custody framing** — ToS §2 states "not a money-services business / not a custodian" as fact. Soften to a position and obtain a FinCEN + state-MTL + \$BRO buy-back-mechanic memo.
* [ ] **⚠ COUNSEL — AML/sanctions reconciliation** — ToS §1.2 and §5.3 carry two different sanctions lists; reference the live OFAC program rather than enumerating, and align the "we screen users" claim with the identity data actually collected (social/email login + read-only key, no KYC).
* [ ] **⚠ COUNSEL — Indonesia PDP Law cross-border transfer** — transfers of Indonesian users' financial data to the US/China need a PDP-compliant mechanism (in addition to the PSE/ITSK reviews below).
* [ ] **⚠ COUNSEL — DPIA** — perform and document a Data Protection Impact Assessment (large-scale sensitive financial data + portfolio monitoring + China transfer trigger Art. 35).
* [ ] **In-product affiliate disclosure (FTC)** — FTC 16 CFR Part 255 requires a clear-and-conspicuous disclosure adjacent to each affiliate link in-product, not only on the policy page.
* [ ] **Per-exchange data-coverage table** — current disclosure is a light inline note; consider a per-exchange breakdown of what data each exchange exposes.

## NeuroWallet (mobile self-custodial wallet + spot trading) — added 2026-07-07

Applied to `terms-of-use.mdx` (v0.8) and `privacy-policy.mdx` (v0.9): NeuroWallet is positioned as a non-custodial embedded wallet (Privy, Solana + Base), spot-only, with trades routed via Relay and priced via Codex. Verified against `neurobro-terminal-mobile` and `neurobro-terminal-backend` (dev + wallet branches).

* [x] **ToS Section 2 restructured** — "Non-Custodial Nature & NeuroWallet": embedded wallet (Privy/TEE), non-custodial key model, "not exchange/broker/custodian/adviser" conduit disclaimer, user-initiated trades + third-party infra + delegated signing, spot-only, eligibility, wallet risk.
* [x] **ToS §5.2 fee** — discloses 0.50% (50 bps) NeuroWallet platform fee + third-party routing/service fee + gas (contradicted the prior "no platform fee" wording, now scoped to Neurobro Web only).
* [x] **ToS §13** — added class-action + jury-trial waiver + 1-year claim limitation (fomo parity).
* [x] **PP** — added NeuroWallet embedded-wallet data, trade/withdrawal activity, wallet net-worth snapshots; Privy/Relay/Codex sub-processors; US/Canada international transfer; retention + deletion + public-ledger warning.
* [ ] **⚠ COUNSEL — key export claim** — per owner instruction the docs state key export is "coming soon." The current build's `exportPrivateKey()` is a stub that throws (no in-app export UI). Ship the export flow before, or shortly after, launch so the "self-custodial / you control your keys" representation is fully supported; otherwise reconcile the wording.
* [ ] **⚠ COUNSEL — delegated signer / custody characterization** — the backend holds a policy-scoped Privy delegated signer and submits user-initiated swaps server-side with no per-tx prompt (session-signer model). Confirm the "limited delegated swap authorization" disclosure adequately characterizes this and does not undermine the non-custodial / not-an-MSB position. Also tighten the on-chain policy allowlist (a broad wildcard exists on Base in the current build — engineering security ticket) before launch.
* [ ] **⚠ COUNSEL — NeuroWallet country blocklist + EU/MiCA** — code ships a placeholder blocklist (US, GB, JP → HTTP 451) flagged "needs legal sign-off," restricts the wallet to paid tiers (pro/ultra), and fails open on unknown geo. Docs currently say "select jurisdictions" generically per owner instruction. Finalize the definitive list and decide the EU position (MiCA: exchange/execution/RTO/advice/portfolio-management exposure even though non-custodial) before launch.
* [ ] **⚠ COUNSEL — MSB/MTL for delegated execution + fee** — taking a 0.50% fee to route/execute user trades via a delegated signer may implicate money-transmission / broker analysis differently than the read-only product. Refresh the FinCEN + state-MTL memo to cover NeuroWallet specifically.
* [ ] **Fiat on-ramp (not yet live)** — Crossmint/Transak/MoonPay are NOT wired (deposit sheet shows "coming soon"); off-ramp is crypto-only. Add on-ramp providers to ToS/PP as independent controllers (KYC/biometric data collected directly from users) only when the feature actually ships.
* [ ] **Provider legal links to verify before publish** — Privy Terms/Privacy (privy.io), Relay Terms/Privacy (relay.link — Cloudflare-blocked to automated checks; confirm exact paths + operating entity Uneven Labs, Inc. in a browser), Codex Terms/Privacy (dashboard.codex.io).
* [ ] **Auth branding vs code** — docs use "Neurobro Pass" for auth; NeuroWallet uses Privy Custom Auth (backend-minted JWT) under the hood. Confirm "Neurobro Pass" remains the correct user-facing brand for the wallet login.

### Non-custodial doctrine — references for counsel (ToS §2 language maps to these)

The §2 non-custodial wording was deliberately drafted to track the regulatory tests below. The **words are only true if the facts hold** — specifically (i) ship key export and (ii) tighten the Base delegated-signer allowlist so it genuinely cannot divert funds.

* **FinCEN "total independent control" test** — FIN-2019-G001 §4.2 (four-factor test; money transmission = "acceptance and transmission of value"), §4.2.1 (unhosted-wallet safe harbor), **§4.2.2 (multi-signature safe harbor: a key acting "at the request of the owner" that "does not have total independent control" is not a money transmitter)**, §4.5.1–4.5.2 (software/tool vs. service). Also FIN-2013-G001. Counsel to confirm exact section numbers against the PDF.
* **Coin Center control test** — "execute unilaterally or prevent indefinitely a transaction"; non-custodial + multi-sig participants are not money transmitters.
* **Commercial precedent for the delegated signer** — Coinbase "spend permissions" / session keys marketed as non-custodial ("under your sole control," scoped, revocable); Privy delegated-actions (user consent, revocable, key never accessible, TEE-only signing). Privy's User Terms make the developer (us) responsible for disclosing delegation and obtaining consent — now done in §2.4.
* **⚠ COUNSEL — MiCA RTO/execution (custody-independent)** — non-custodial does NOT exempt: receiving swap requests and transmitting them to Relay is likely **Reception & Transmission of Orders (Art. 3(1)(23))**, and the delegated signer risks tipping into **Execution of Orders (Art. 3(1)(21))**. Recital 22's "fully decentralised without any intermediary" carve-out does not apply to a fee-charging interface with a legal operator and backend execution. This is a licensing analysis for any EU launch, not a drafting fix. ESMA Level-3 guidance on the decentralization test expected 2026.
* **Weakening phrases to keep out of docs/marketing/UI** — "we execute trades for you / on your behalf," "we hold/store your balances," "funds in your Neurobro account," "we send/move/transmit your crypto," "we control routing," "we can pause/freeze/seize/reverse," "spread," "we fill your order." (ToS audited; keep the app UI aligned.)

## NeuroAPI (developer API) — added 2026-07-21

New page `legal/api-terms.mdx` (v0.2, DRAFT) created for GitHub issue #87. Also applied to `terms-of-use.mdx` (v0.9) and `privacy-policy.mdx` (v0.10), and added to the Legal nav in `docs.json` + linked from the NeuroAPI product page (`technical/neuroapi/index.mdx`). Evidence base for the copy: whitepaper NeuroAPI page + `neurobro-terminal-backend` agent\_core (`agent_neuroapi.py`, `neuroapi_pipeline.py`, `neuroapi.yaml`), read-only. NeuroAPI = paid public API, single-turn/stateless, caller sends a question (+ optional custom system prompt + optional output schema), returns AI-generated analysis across crypto/stocks/forex/commodities; three modes (FAST/SMART = DeepSeek, MAX = OpenAI). The API HTTP service (auth/billing/rate-limit/logging) is a separate origin (api.neurobro.ai / neuroapi backend) not checked out locally.

* [x] **API Terms page** — grant/scope, API-key security, permitted/prohibited uses (rate-limit circumvention, resale/redistribution, competing-model training, reverse engineering, infra abuse, unlawful use, Output misrepresentation, unlawful Input), fees/plans/rate limits (by reference), Output rights + AI disclaimers + End-User disclosure, data/privacy + third-party AI transmission, availability/deprecation, suspension/termination, disclaimers/indemnity/governing law (by reference to ToS §11–13).
* [x] **ToS incorporation** — NeuroAPI added to Operator & Scope services list; API Terms incorporated by reference (API Terms control for NeuroAPI on conflict); clarified NeuroAPI ≠ read-only exchange "API keys" (ToS §3).
* [x] **PP disclosures** — new NeuroAPI developer account & request-data accordion (API-key identifiers, request Inputs/Output, usage metadata; stateless single-turn); LLM-provider section extended to NeuroAPI Inputs (DeepSeek/OpenAI); Summary bullet + retention entry.
* \[\~] **⚠ COUNSEL — Output rights + training conflict (training half RESOLVED in drafting)** — Per owner instruction (2026-07-24), the *training* half is now resolved for NeuroAPI: ToS §9.2 amended to carve NeuroAPI Inputs/Output out of the perpetual training license; API Terms §7.3 states an affirmative "we do not train on your Inputs/Output" commitment; API Terms §8.2 + PP §7 disclose that third-party providers train independently (OpenAI does not train on API data; DeepSeek may). **STILL OPEN:** (a) the Output-rights *model* — license (drafted) vs assignment, and reconciliation with ToS §9.1's blanket ownership claim; (b) confirm the no-training commitment matches the actual API logging/retention pipeline (separate origin); (c) the consumer-app ToS §9.2 vs PP §7 conflict is unaffected by this API carve-out and remains tracked separately.
* [ ] **⚠ COUNSEL — DeepSeek/China routing of Developer Inputs** — Developer Inputs may be routed to DeepSeek (China) by the backend's automated routing (currently the FAST/SMART tiers); Inputs may be at scale and may contain End-User personal data. **Disclosure strengthened (2026-07-24):** API Terms §8.2 now describes automated routing (no mode→provider mapping pinned in the public terms, per owner instruction) and names DeepSeek's China storage + model-training use with a citation, telling Customers to treat every Input as if it may reach any listed provider. Disclosure alone likely does not cure the transfer — still decide whether DeepSeek must be excluded for EU/UK Inputs or a region-pinned model offered; refresh the TIA.
* [ ] **⚠ COUNSEL — controller/processor + DPA** — where a Customer submits its End Users' personal data as Input, Neurobro likely acts as the Customer's *processor*, requiring a Data Processing Agreement / API-specific data terms and Art. 28 language. None exists yet.
* [ ] **⚠ COUNSEL — fee model reconciliation** — marketing states subscriptions from \$49.99/mo + enterprise; the internal pipeline is implemented as pay-per-call with no per-call tier gating. Confirm whether NeuroAPI is billed by subscription, metered usage, or both, before publishing (API Terms §6.1 currently defers to the pricing page + ToS §5.1).
* [ ] **⚠ COUNSEL — x402 coverage** — decide whether these API Terms also govern the x402 pay-per-request interface (same agent/toolset, no API keys) or whether x402 needs its own terms.
* [ ] **TODO-owner — publish concrete rate limits** — the product docs state no numeric rate limits/quotas/concurrency caps; API Terms §6.2 references "published limits" generically. Populate real per-plan figures.
* [ ] **TODO-owner — API retention periods** — confirm retention for NeuroAPI Inputs, Output, and usage/billing logs (not verifiable from the docs repo) so PP §4 can state a concrete period instead of "pending confirmation".
* [x] **Entity-name inconsistency — RESOLVED (2026-07-24)** — Aligned the whole corpus to **NeuroFoundation, LLC** (matching `legal/license.mdx`) per owner instruction, in a dedicated commit: renamed across Terms of Use, Privacy Policy, API Terms, Affiliate Disclosure, Account Deletion, and the Company page. Counsel to confirm this is the correct registered legal name.

## Data Security Statement (new document — not yet started)

* [ ] **Create a Data Security Statement** — new legal page describing the security model.
* [ ] **Encryption model** — exchange credentials protected with AWS KMS envelope encryption (AES-256-GCM), a unique per-record data-encryption key, encrypted blob stored as binary in PostgreSQL; production-isolated CMK (`alias/neurobro-exchange-credentials-prod`); supports in-place credential rotation with key-version audit trail.
* [ ] **Read-only access model** — no execution capability (`supports_execute = False` hardcoded; sandbox/paper-trading disabled).
* [ ] **Transport & scoping** — HTTPS/TLS in transit; all data user-scoped; cascading deletion.
* [ ] **Describe memory handling honestly** — credentials held in memory only for the duration of a single connect/sync operation; do not overstate (Python cannot guarantee explicit memory zeroization).
* [ ] **Self-hosted observability** — note that the memory sync service uses no third-party error-tracking SDK; observability there is self-hosted (Loki). (Product analytics is also self-hosted via Matomo.)

## Regulatory / jurisdiction reviews

* [ ] **Indonesia PSE / foreign ESO registration** — review whether registration as a foreign Electronic System Operator (PSE) is required.
* [ ] **OJK ITSK framework** — review applicability of the OJK ITSK framework (covers technology innovation affecting products, activities, services, or business models in the digital financial ecosystem).
* [ ] **⚠ COUNSEL — confirm country blocklists** — code blocklists are "starter data from 2026-05-18 legal research" and must be counsel-confirmed before launch; specifically flagged: Indonesia, the UK FCA regime, and Bybit-in-Malaysia.
* [ ] **⚠ COUNSEL — core-service jurisdiction restriction** — decide whether the core portfolio/exchange-connect service (not just affiliate links) needs country-based access control.

## Product documentation

* [ ] **API key creation guidelines** — add per-exchange API key creation guidelines, broken down by supported region, covering required permissions (read-only) and regional availability.

## Engineering prerequisites (block accurate legal copy)

* [ ] **Scrub Sentry SQL parameters** — SQLAlchemy integration may capture SQL query parameters (user IDs, financial values) despite `send_default_pii=False`; add explicit scrubbing before claiming no financial data leaves systems for monitoring.
* [ ] **Sanitize exchange error logs** — raw exchange error messages (`str(exc)`) can contain balance amounts or masked API-key fragments; sanitize before launch.
* [ ] **Enforce `REDIS_PASSWORD` in production** — the sync queue is unauthenticated if unset.
* [ ] **Decide on a retention-purge job** — confirm/decide whether old trade/order/ledger/transfer history is purged on a schedule.
