Useful capabilities, with meaningful limitations to understand.
Gunbot is a strong choice for technically capable users who want trading logic and encrypted exchange secrets on their own machine. Local deployment avoids a shared SaaS credential store, but it does not remove risk: exposed dashboards, weak HTTPS, unpatched hosts and stolen configuration files can be serious failures. Feature depth is high; usability and legal-operator transparency trail polished cloud peers.
Local encrypted key storage and token authentication are positive; user-managed host security and remote exposure can create serious risk.
Architecture, prices and features are clear, but the legal operator, registration and ownership are not.
Gunbot has a long public product history and active technical documentation.
Unlimited pairs, Grid bots, native and custom strategies, DeFi, backtesting, simulation and REST control provide deep flexibility.
Installation, exchange setup and host administration create a higher technical barrier.
Lifetime and subscription options are public, though promotions make current purchase prices volatile.
Current documentation, email and community support are available; response quality was not tested.
Backtesting and simulation are strong, but no independently audited live-return record exists.
What this score means It evaluates the product and available evidence. It does not predict returns or eliminate trading risk.
Trust profile
Thirteen disclosed factors create the calculated Trust Score.
A current legal operator was not located.
Factor score: 42/100No company registration was verified.
Factor score: 25/100Current ownership and accountable leadership are unclear.
Factor score: 38/100A long product history is supported by public releases and documentation.
Factor score: 90/100Plan structures are clear; promotional prices change frequently.
Factor score: 84/100Local encryption and hardening guidance are documented without independent assurance.
Factor score: 84/100Local exchange connections and the authenticated REST API are extensively documented.
Factor score: 92/100Official guidance says withdrawals should usually remain off; exchange requirements vary.
Factor score: 90/100Technical documentation is extensive and current.
Factor score: 92/100No independent outcome record was found.
Factor score: 42/100Support channels exist; service levels were not measured.
Factor score: 74/100No qualifying product incident was identified; local user compromises may not become public.
Factor score: 55/100The self-hosted software role is apparent, but legal entity and jurisdiction are unclear.
Factor score: 45/100Red flags & concerns
Context that should inform—not replace—your own assessment.
During our latest review. This does not mean the platform is risk-free.
Public dashboard exposure, missing HTTPS or weak host credentials can compromise the bot.
Current company identity and registration were not found.
Lifetime list and sale prices vary; confirm checkout terms.
What we verified
Checks completed during the latest research cycle.
Gunbot product and safety research
Company, product, permission and regulatory evidence reviewed separately.
Is Gunbot legit?
The product has long-running releases, current documentation and active pricing, but current company registration and ownership are not clear.
Technical transparency is far stronger than corporate transparency.
Operator and legal sources: no dedicated source in the current evidence set; see the full source list and stated limitations below.
Is Gunbot safe?
Local encrypted secret storage is a meaningful architectural distinction. Security depends on host hardening, HTTPS, dashboard access, backups, updates and safe support exports.
How Gunbot works
Gunbot runs on Windows, macOS or Linux, reads market data and submits orders from the user's host. A token-authenticated REST API can control the local instance.
Trading bots and automation features
Gunbot suits advanced users seeking Grid, native, custom JavaScript and DeFi automation with programmatic control.
Supported exchanges
Binance, Bybit, Kraken, KuCoin, OKX, Bitget, Hyperliquid, dYdX
Pricing
Standard, Pro and DeFi are lifetime licenses; Unlimited is $29 monthly. Sale prices shown on the plans page are time-sensitive.
Pricing source: Gunbot plans (Primary) · Gunbot pricing FAQ (Primary)
Custody model
Self-hosted, non-custodial software; exchange funds remain on exchanges
Security
Gunbot's local model removes a central cloud key database but makes each installation its own security perimeter.
Keep the GUI private, configure HTTPS for remote access, patch the host, use trade-only keys, restrict IPs and never share raw config files.
API and withdrawal permissions
Exchange credentials are encrypted and stored locally. Users configure required exchange trading scopes and should disable withdrawals. Withdrawal status: Usually unnecessary and should remain disabled.
Security and permission sources: Gunbot security measures (Primary) · Gunbot API introduction (Primary) · Gunbot Live security basics (Primary)
Regulatory information
Gunbot appears to provide software rather than custody or intermediation; without a verified legal operator, jurisdictional conclusions remain limited.
Regulatory and service-scope sources: no dedicated source in the current evidence set; see the full source list and stated limitations below.
Performance evidence
Backtesting and simulation are strong, but no independently audited live-return record exists.
Claim verification
Source, claim type, evidence, status and analyst note are shown separately.
“API secrets never leave your control”
- Claim source
- Open company source
- Evidence found
- Gunbot documents local encrypted storage rather than a shared cloud key store.
- Analyst note
- Local malware, backups or remote exposure can still leak secrets; implementation was not independently audited.
“No user data collection”
- Claim source
- Open company source
- Evidence found
- The company states there is no tracking or telemetry; no independent network/privacy assessment was located.
- Analyst note
- This is a provider assertion.
“Unlimited gridbots”
- Claim source
- Open company source
- Evidence found
- Current plan descriptions state no Gunbot cap, while exchange, hardware and API limits still apply.
- Analyst note
- Unlimited licensing does not mean unlimited practical capacity.
Security incident history
Documented events and bounded public-source checks, with entity scope preserved.
Public-source incident check
No material centralized Gunbot security incident was identified in reviewed sources.
- Provider response / research note
- Local compromises may be private and unreported; this is not a clean-history guarantee.
Strengths & limitations
Strengths
Local encrypted API-key storage
Deep custom strategy support
Lifetime license options
Strong technical documentation
Limitations
–Requires secure host administration
–Legal operator not verified
–Steeper learning curve
–No independent performance audit
Who may find it useful
Technical self-hosting users
Custom strategy developers
Traders wanting local credential control
Who should look elsewhere
–You cannot secure and maintain a host
–You want turnkey cloud onboarding
–Corporate transparency is essential
Gunbot alternatives and comparisons
Alternatives are selected for overlapping workflows, with the main distinction shown.
Frequently asked questions
Is Gunbot cloud-hosted?+
Core Gunbot runs on the user's Windows, macOS or Linux host.
Does local hosting make Gunbot safe?+
Not automatically. The user must secure the host, network, dashboard and backups.
Can Gunbot withdraw funds?+
Withdrawal permission is generally unnecessary and should remain disabled.
Sources & evidence
Company-provided information is labeled and not treated as independent validation. Research coverage: 7/9; evidence confidence: Moderate.
Research changelog
Conclusions may change when new evidence appears.
Reviewed local architecture, pricing, API, security and company gaps.
Gunbot: 72/100
Gunbot is a strong choice for technically capable users who want trading logic and encrypted exchange secrets on their own machine. Local deployment avoids a shared SaaS credential store, but it does not remove risk: exposed dashboards, weak HTTPS, unpatched hosts and stolen configuration files can be serious failures. Feature depth is high; usability and legal-operator transparency trail polished cloud peers.
Research disclaimer This review is informational and not financial, investment, legal or security advice. Scores evaluate disclosed product qualities and evidence—not profitability, solvency or safety. Features, prices and eligibility can change.
We may receive compensation from some outbound links. Commercial relationships never affect scores or research conclusions. Read our policy.