This project reads public market data. It does not require credentials and cannot submit orders. Never add API keys, account data or secrets to examples, issues, notebooks or fixtures.
Report vulnerabilities through the repository's private vulnerability-reporting feature. Avoid publishing exploit details before a fix is available.
REST hosts and WebSocket services are fixed in code. Paths are restricted to API v5. Requests use timeouts and bounded retries. Stream captures require a time or message limit. Output filenames are created locally; no exchange archive is extracted by this package.
These controls reduce risk but do not make third-party data trustworthy. Validate schemas and sizes, inspect large files before opening them, and keep dependencies updated.