Can NoVo be hacked? The honest answer for any software is: no system is perfectly unhackable, so the real question is what's the worst a breach could do? Because NoVo is non-custodial, even a worst-case breach cannot withdraw your money — and that structural fact is the most important part of the security story.
Why non-custody limits the damage
The catastrophic hacks in this space steal money — they hit a service that holds customer funds and drain the pot. NoVo has no such pot: your money stays in your own broker account, and NoVo's access is scoped to trading, not withdrawal. So even in a worst-case compromise, an attacker cannot transfer your funds out — there's no withdrawal permission to abuse and no custodial balance to take. The single most damaging outcome (losing your capital to theft) is structurally off the table.
What a breach could and couldn't do
Honesty about the bounds: the worst a compromise of the trading connection could plausibly do is place trades in your account — which is exactly why your hard boundaries matter (NoVo can't trade outside your limits), why stops rest at the broker, and why you can revoke the broker connection instantly at any sign of trouble. It couldn't withdraw your money (no permission), because non-custody removes that capability entirely. The damage ceiling is bounded by design, not just by defenses.
The question isn't “can it be breached?” — nothing is unbreakable. It's “can a breach take my money?” With non-custody, the structural answer is no.
The honest security posture
Good security is layered: sensible protection of the connection, the non-custodial architecture that caps the worst case, your boundaries that bound any trading, protective stops, and your ability to revoke access. No one honest promises “unhackable” — but the right question is damage limitation, and non-custody gives the strongest possible answer: your capital can't be stolen through NoVo, because NoVo never holds it. That's security by architecture, which is the kind that actually holds up.