COMPLIANCE · REGULATORY POSTURE · METHODOLOGY
How LumenBotFi stays on the right side of the line.
We've built LumenBotFi so you stay in control of your money at every moment. This page explains what we are, what we are not, how the service is architected, how we manage risk, and the legal framework that lets us operate as a non-custodial Bitcoin automation service.
Last reviewed · April 2026 · v2.0
On this page
- Built on trust
- What we are — and aren't
- Why non-custodial matters
- Regulatory posture & legal framework
- Methodology & strategy architecture
- Execution & operational controls
- Risk taxonomy
- Security & data protection
- Jurisdiction & availability
- Changelog
- Contact for regulatory & diligence inquiries
1 · Built on trust
Four non-negotiable design principles shape how LumenBotFi operates. Every strategy, pricing decision, and operational control flows from these four.
🛡
Non-custodial
Your funds stay in your exchange account. We never hold, move, or receive them.
🔑
Trade-only API
An API key you create with no withdrawal permission. You can revoke it with one click, any time.
⚖️
Service, not advice
We provide automated execution infrastructure — not personalized investment advice or financial planning.
📜
Rule-based AI
Our models size a custom strategy per account using disclosed, rule-based inputs. The rules are the same for every account; the sizing is what changes.
2 · What LumenBotFi is — and isn't
This is the shortest honest answer we can give to "what is this company, legally?" — stated as a binary, with no hedging.
We are
- A software service that runs an automated Bitcoin strategy against your own exchange account
- A non-custodial platform — your exchange holds every asset, always
- Transparent about our subscription rate, our strategy rules, and our architecture
- A publisher of general-market information and automated execution tools, not a fiduciary
- Available only to users who have signed our Service Agreement and Risk Disclosure
- A US-incorporated entity with Ohio as its governing-law jurisdiction
We are not
- A registered investment adviser (RIA), broker-dealer, or futures commission merchant
- A custodian — we cannot hold, transfer, or withdraw your funds
- A money services business (MSB) — we don't transmit, convert, or settle money
- A source of personalized investment advice — we don't know your situation
- A guarantee of profit — automated Bitcoin strategies involve real risk of loss
- A bank, trust, lender, or FINRA-regulated entity
3 · Why non-custodial matters
A custodial platform holds your money. A non-custodial platform never touches it. The distinction isn't semantic — it determines which regulatory regime applies, what happens if the platform fails, and whether you ever have to trust the platform with your capital.
What "custody" actually means
Under SEC, CFTC, and FinCEN definitions, custody generally means the ability to receive, hold, transfer, or direct a client's assets. A platform that cannot initiate a withdrawal from your account — and cannot receive your assets into its own wallet — is not a custodian of those assets. LumenBotFi falls into that second category by design.
The mechanical test: If LumenBotFi's servers went offline permanently, your Bitcoin would remain in your exchange account, under your login credentials, accessible to you without our involvement. That is the operational definition of non-custodial and it applies every minute of every day.
How the trade-only API key works
When you connect your exchange, you generate an API key inside your exchange's own security settings. You explicitly select a permission scope of "view balances" and "place spot trades." You explicitly leave the "withdraw" permission unchecked — many exchanges now require a multi-step confirmation (email + 2FA + IP allow-list) before any withdrawal permission can be granted to an API key, so even an accidental click can't enable it. You paste that key into LumenBotFi. The strategy runs. You revoke the key with one click in your exchange dashboard any time, and our access stops immediately.
IP allow-listing and additional restrictions
Where supported by the exchange, we recommend you also IP-allow-list our static inbound addresses (provided to you in your dashboard) so the API key is rejected if it's ever presented from anywhere else. This adds a second layer of control above the permission scope: even if the key leaked, it would only work from our documented IPs.
What happens in a corporate-continuity event
If LumenBotFi ceased operations — whether voluntarily, by acquisition, or through unforeseen circumstance — the following is true by architecture, not by policy:
- Your Bitcoin stays where it is. It was never on our balance sheet and was never on our servers.
- Your API key is revokable by you. You don't need our cooperation to end the relationship.
- No bankruptcy estate, creditor, or receiver has a claim on your funds, because your funds are not and never were our assets.
- Your exchange account is unaffected. You retain full access to it at all times.
That is the single most important operational feature of this company, and it is true because we architected it to be true — not because we promised it.
4 · Regulatory posture & legal framework
Our legal framework is designed to be consistent, disclosed, and defensible. The summary below is not legal advice — it is a description of how the business is structured and what assumptions we operate under.
The publisher-exception reasoning
Under long-standing federal doctrine (Lowe v. SEC, 472 U.S. 181 (1985), and subsequent SEC guidance), publishers of general-market information that is not tailored to an individual client's particular circumstances are not investment advisers within the meaning of the Advisers Act. LumenBotFi sizes a rule-based strategy using only inputs the user provides (amount to allocate, exchange) — it does not know the user's tax situation, time horizon, overall financial picture, or personal objectives, and it does not hold itself out as an adviser. This places the service on the publisher side of the line rather than the adviser side.
Why we are not a broker-dealer or FCM
Broker-dealer registration is triggered by, among other things, effecting transactions for the account of others or receiving transaction-based compensation. LumenBotFi never effects transactions for anyone — the user's own exchange effects them, under the user's own account. Our compensation is a fixed monthly or annual subscription that does not scale with trade volume, P&L, or assets under management. Futures commission merchant registration likewise does not apply because we do not accept customer funds and do not transact in regulated futures.
Why we are not a money services business (MSB)
FinCEN's definition of money services business covers money transmitters, currency dealers, and certain other entities that move value for customers. We do not transmit, exchange, convert, or settle money or crypto-assets for users. The user's exchange handles all of that. We are a software service that issues trade instructions via authenticated API; we do not sit in any value chain.
Governing law, venue, arbitration
ItemTerms
Governing lawState of Ohio, USA — without regard to conflict-of-law principles
VenueState and federal courts located in Cuyahoga County, Ohio for matters not subject to arbitration
Dispute resolutionBinding individual arbitration per the AAA Consumer Arbitration Rules; class and collective actions waived
Exceptions to arbitrationSmall-claims actions; claims for injunctive relief to protect intellectual property
Claim limitation periodOne (1) year from the date the cause of action accrues
Liability capThe greater of (a) the fees paid to LumenBotFi in the three (3) months preceding the claim or (b) US$5.00
Excluded damagesIndirect, incidental, consequential, special, exemplary, punitive, lost-profits, and lost-data damages
DMCA agentDesignated under 17 U.S.C. § 512(c). Contact details in our Terms.
Service of processAccepted via our registered agent at the address in our Terms.
Note: These terms are summarized here for transparency. The governing legal text is in the Terms & Conditions and the Service Agreement you sign at subscription. Where this page and those documents differ, those documents control.
Marketing & disclosure rules we hold ourselves to
- No guaranteed returns. We never use "guaranteed", "risk-free", "profits", or "returns" as a promise, in any channel.
- Past-performance caveat. Any chart or performance figure includes a standing disclosure that historical or illustrative results do not guarantee future outcomes.
- Cited figures get sources. We don't invoke third-party performance numbers without dating them and linking or citing the source.
- Testimonials policy. Customer testimonials, when published, are accompanied by a representative-results caveat; we do not pay for testimonials.
- Fiduciary disclaimer. Every page repeats that LumenBotFi is not a registered investment adviser and that nothing on the site is personalized advice.
Ongoing regulatory monitoring
Rules around automated crypto services evolve. We monitor SEC, CFTC, FinCEN, state-level money-transmitter rules, EU MiCA, UK FCA guidance, and major developments in our operating jurisdictions. When a rule change would meaningfully affect what we can offer, we give users advance notice and a window to adjust before the change applies.
5 · Methodology & strategy architecture
Every LumenBotFi account runs the same rule-based methodology, with the same rules for every user and different sizing per account. Here is how it works end-to-end.
Rule-based Disclosed inputs Deterministic execution Auditable trail
5.2 AI sizing — what the model actually does
The "AI" component is strictly a sizing allocator. It does not change the strategy rules, does not trade outside the published rules, does not learn from or condition on any individual user's behavior, and does not use any off-platform data about the user. What it does:
- Takes disclosed inputs: allocation size, exchange, and current market-regime features (volatility, trend, range width).
- Outputs allocation weights across the published rules at a given regime.
- Re-evaluates on a fixed cadence: weights are refreshed on a schedule, not continuously, so the behavior is observable and testable.
- Is bounded: every rule has a hard minimum and maximum weight — the model cannot concentrate the entire allocation in one place.
The sizing model is a rule-based allocator with bounded outputs. It is not a reinforcement-learning agent making unconstrained decisions, and it is not a large language model.
5.3 Backtesting & validation protocol
Every strategy version we ship passes through a three-stage evaluation:
- In-sample calibration on a reference period with documented start and end dates. Parameters are fit here and then frozen.
- Out-of-sample validation on a walk-forward period not used in calibration. Performance is measured without any further parameter tuning.
- Paper-trade live for a minimum shake-down window on real market data before any user account runs it.
We retain the full parameter set, input data snapshot, and result log for every ship so the calibration is reproducible.
5.4 Parameter change management
Strategy rule changes and parameter updates follow a documented change-management process: proposal → paper replay → review → release. Parameter changes are versioned and logged. Material changes trigger a user-facing release note.
5.5 What the strategy does NOT do
- No leverage by default. Spot-only unless a user explicitly opts in on an exchange that offers leverage.
- No overnight margin calls by the platform. Any margin dynamics are between the user and their exchange.
- No cross-account pooling. Each user's account is siloed.
- No front-running, wash trading, or order-flow arbitrage. We don't inspect or trade ahead of any user's orders.
- No payment-for-order-flow. We receive no rebate or kickback from any exchange or market maker.
6 · Execution & operational controls
6.1 Order flow
When a module generates a signal, the platform issues an authenticated API request to the user's exchange using the user's trade-only API key. The request specifies symbol, side, size, and order type. The exchange's matching engine fills (or rejects) the order. The fill is posted back to the platform as a confirmation event and written to the user's execution log.
6.2 Pre-trade checks
Before any order is issued, the platform verifies:
- The user's allocation cap has not been breached for the relevant strategy module.
- The API key is alive and has the expected permission scope (trade-only; no withdrawal).
- The exchange's order endpoint is responding within a health threshold.
- No kill switch is active at the account, strategy, or platform level.
6.3 Kill switches
Three levels of halt are available and auditable:
- Account-level pause. The user can pause their own account from the dashboard, instantly. Existing orders are cancelled; new orders stop.
- Strategy-level halt. Operations can halt a single strategy module across all accounts (e.g., during an exchange outage affecting only one symbol).
- Platform-level halt. Operations can halt the entire platform (e.g., during a suspected security event). All user keys remain revokable by the user at the exchange regardless.
6.4 Monitoring, alerting, incident response
The platform emits operational telemetry — order acceptance rates, API latency, exchange health signals, account-level drift indicators. Anomalies alert the operator.
6.5 Business continuity & disaster recovery
The execution infrastructure is designed so a user's funds are safe even in the worst-case platform failure, because they are never in our custody.
7 · Risk taxonomy
Every investor who looks at this business asks the same question: what can go wrong, and who wears the loss? Here is the honest map.
RiskWhat it meansWho bears itWhat we do about it
MarketBitcoin price moves against open positionsUserDisclose, size within user's allocation, apply the published rules so no single direction is overweighted
StrategyA module underperforms out-of-sampleUserWalk-forward validation, paper-trade shake-down, versioned rollout, kill switches
CounterpartyUser's exchange fails, is hacked, or freezes withdrawalsUser (the exchange holds the assets)Publish supported exchanges with honest notes; user chooses which to connect
ExecutionOrder rejected, partially filled, or delayedUser (in P&L)Retry logic, rate-limit backoff, order-state reconciliation, user-visible execution log
API-key compromiseA key leaks and is misused within its permission scopeUser (limited to trade activity, never withdrawal)Trade-only permission scope is mandatory; IP allow-listing recommended; one-click revocation at exchange
Platform outageOur infrastructure is unavailableUser (foregone trades)User can operate their exchange directly while we're down
Security incidentUnauthorized access to platform data or configurationLumenBotFi + user (exposure is API keys, not funds)Least-privilege access, encryption at rest, audit logging, IR playbook, user notification policy
RegulatoryA rule change restricts what we can offerLumenBotFiOngoing monitoring, advance user notice, architected for minimum regulatory surface
LiquidityWide spreads or thin books on a venueUser (worse fills)Limit-order default where appropriate, venue health checks, halt module if spreads exceed thresholds
ConcentrationSingle-asset exposureUserDisclose at subscription; user's allocation sizing is their decision
Bitcoin markets are risky. Prices can move rapidly in either direction. Past performance — including backtests, hypothetical results, and prior strategy performance — does not guarantee future results. Automated strategies can and do experience losing streaks, periods of drawdown, and unexpected outcomes during extreme market events (flash crashes, liquidity gaps, exchange outages).
Only run a sleeve you can afford to lose. LumenBotFi provides a service and execution infrastructure; every order executes inside your own exchange account under a trade-only API key you create and control. You are responsible for the funds in your exchange account and the decision to pause, resume, or revoke the strategy's access.
8 · Security & data protection
8.1 What we collect
The minimum required to run the service:
- Account identity: name, email, password hash (never the plaintext password)
- Exchange API credentials: key and secret, stored encrypted at rest with a hardware-backed key management system
- Execution logs: orders issued, fills received, errors encountered — your own transparency ledger
- Billing data: handled by Stripe; we do not store full card numbers
8.2 What we don't do with your data
- We do not sell your data.
- We do not use your execution activity for market-making or order-flow programs.
- We do not share your data with advertising or analytics vendors beyond minimal product telemetry (opt-out available).
- We do not train models on user-identifiable execution data.
8.3 Controls
- Encryption at rest for API credentials, backups, and personally identifying information.
- Encryption in transit via TLS 1.2+ for all inbound and outbound traffic.
- Least-privilege access controls with role-based permissioning.
- Audit logging of all privileged actions, retained per our record-retention schedule.
8.4 User rights
You can request export, correction, or deletion of your personal data at any time. Full detail — including the narrower definitions and processes required by GDPR, the UK GDPR, the CCPA/CPRA, and comparable state laws — is in our Privacy Policy.
8.5 Sub-processors
A current list of sub-processors (cloud infrastructure, email, billing, customer support) is available on request and referenced in the Privacy Policy. Material changes to the sub-processor list are announced in advance of going live.
9 · Jurisdiction & availability
LumenBotFi currently operates in the United States and in other jurisdictions where our supported exchanges are active and where our service model is compatible with local rules. Rules around automated crypto services vary widely by country and change often. Before using LumenBotFi, you should consult your own attorney or local advisor to confirm it is permitted where you live. You, not LumenBotFi, are responsible for your own jurisdictional compliance — we do not provide legal guidance on whether the service is right for your local rules, and we are not responsible for your use of it in your jurisdiction. If you are unsure, contact us at info@lumenbotfi.com before subscribing.
Sanctions & restricted-party screening
We do not knowingly provide the service to persons or entities on OFAC's Specially Designated Nationals list, EU or UK consolidated sanctions lists, or equivalent lists in the jurisdictions where we operate. Our supported exchanges perform their own KYC and sanctions screening as a condition of their accounts; we rely on that screening and reserve the right to perform our own.
10 · Changelog
Material changes to this page and the positions it describes:
2026-09-03 · v2.2
Removed the four-strategy-module description, canary-rollout and on-call/playbook statements, and the Bitcoin-only wording, to describe only what the platform does today.
2026-09-02 · v2.1
Migrated to app.lumenbotfi.com. Removed claims pending re-substantiation on the new platform (SOC 2 readiness, multi-region redundancy, SSO-enforced admin access, backup/recovery cadence) and the diligence-package section.
2026-04-23 · v2.0
Investor-grade rebuild. Added methodology depth (strategy stack, AI sizing, backtesting protocol, change management), operational controls (kill switches, monitoring, BCP/DR), detailed risk taxonomy, expanded security and sub-processor disclosure, explicit diligence package, and a formal table of contents.
2026-04-22 · v1.0
Initial compliance page. Four pillars, what we are / are not, non-custodial explanation, basic regulatory posture, risk disclosure, jurisdiction.
11 · Contact for regulatory & diligence inquiries
Serious inquiries — regulatory, legal, investor, enterprise diligence, or a journalist working on a story — should reach us at info@lumenbotfi.com with a brief description of the request and a preferred timeline. We respond within two US business days on items of this kind.
Disclosure · Required reading
Risk Disclosure.
This page is the canonical risk disclosure for LumenBotFi. The three required disclaimers below appear in our customer agreement, in our marketing materials, and across the site. They are the floor, not the ceiling.
Last updated: April 25, 2026 · Effective date: April 25, 2026
The three required disclaimers
1. Risk of trading (RISK_BASIC)
Trading cryptocurrencies and using automated execution carries substantial risk, including the risk of total loss of principal. Past performance does not guarantee future results. Markets can move sharply against your position. You are solely responsible for your trading decisions and outcomes.
2. Non-custodial (NON_CUSTODIAL)
LumenBotFi is non-custodial. Your funds remain in your own exchange account at all times. LumenBotFi does not take possession of your crypto, does not hold private keys, does not hold seed phrases, and does not have withdrawal permission on your accounts. We connect via trade-only API keys with withdrawal disabled.
3. Not an adviser (NOT_ADVISOR)
LumenBotFi is not a registered investment adviser, broker-dealer, or commodity trading advisor. Nothing on this site or in any LumenBotFi communication constitutes investment, legal, or tax advice. LumenBotFi does not recommend specific securities, market timing, or position sizes. The strategies you elect are your decisions; we provide the execution surface.
Crypto-specific risks
- Volatility. Crypto prices can move 10% or more in a single day. Sudden moves can fill, exhaust, or invert the ladders that automated strategies rely on.
- Custody at exchange. Your funds are held by the exchange you choose. If the exchange fails, freezes withdrawals, or is hacked, your funds may be lost or inaccessible. LumenBotFi cannot insure or recover funds held by an exchange.
- Exchange insolvency. Exchanges have failed in the past. Maintain reasonable balances at any single venue and consider redundancy.
- Market manipulation. Crypto markets are less regulated than traditional securities markets and are more susceptible to wash trading, spoofing, and pump-and-dump activity.
- Regulatory change. The legal status of crypto trading, automation, and tax treatment can change with little notice and may affect your account in ways neither you nor LumenBotFi can predict.
- Tax reporting. Automated trading produces many taxable events. You are responsible for tracking and reporting them. We can export trade history; we do not file taxes for you.
Automation-specific risks
- API latency and outages. Order placement depends on the exchange's API. Latency, throttling, or outages can cause missed fills, partial fills, or duplicate orders.
- Exchange downtime. If your exchange is down, no automation can place orders for you. Strategies do not "catch up" silently after an outage; some require manual reset.
- Strategy underperformance. Any given strategy may underperform a buy-and-hold approach, lose money in a directional market, or fail to recover from a deep drawdown. You should size each strategy with that possibility in mind.
- Unintended interactions. Other software you connect to the same account, manual trades you place, or competing strategies running in the same exchange account can interact with LumenBotFi's orders in unexpected ways.
- Parameter risk. The parameters you elect (grid spacing, ladder depth, allocation percentages) materially change risk and reward. Small parameter changes can produce large outcome differences.
Customer acknowledgment
By using LumenBotFi, you acknowledge that you have read this Risk Disclosure, that you understand the risks summarized above, that you are solely responsible for your trading decisions, and that LumenBotFi is providing software for execution — not investment advice, not custody, and not a guarantee of profit.