Wallet
One wallet the engine spends from, and any number of wallets you have proved you control. ROCK in either counts toward the auto-trade gate.
No wallet yet. One is created on first sign-in where the deployment holds a master key.
The private key is encrypted at rest with a master key held only in the server process. It is never written to the database, never logged, and no endpoint returns it — there is no export, by design. Fund this wallet with what you intend the engine to risk and no more.
Nothing linked. Link the wallet your ROCK is already in and it counts toward the gate — you do not have to move it.
Linking grants no spending power of any kind. There is no key column for a linked wallet anywhere in the schema and no code path that could sign for one; it is read only to count ROCK toward the gate.