Security approach
Visible boundaries for a paper-first beta with limited, manually confirmed live capability.
Security overview, not a certification or audit claimSecurity model
Paper mode is the default. The architecture separates extension code, local encrypted wallet material, and protected provider credentials. This reduces exposure but does not eliminate browser, device, software, network, or user risk.
Local wallet vault
Wallet secrets are encrypted locally. Supported transactions are signed locally. A funded live test requires an unlocked vault, a Solana wallet, an encrypted backup, an explicit typed live-mode confirmation, and a second confirmation for each supported swap.
Protected provider routes
Private RPC and market-data credentials remain on the server and are not included in the downloadable extension. Authenticated proxy routes restrict origin and method access. Public health checks do not expose credentials.
Limited live controls
Current approved live scope is limited to manually confirmed Solana instant swaps. Live sessions are timed. Automatic execution, copy trading, mainnet limit orders, stop orders, EVM execution, and Robinhood execution are not available.
Transactions are not guaranteed to be included or to execute at a quoted price. Mandatory network and protocol costs may still apply.
Operational practices
Deployment secrets should remain outside source control, environment files should be access-restricted, logs should avoid secret values, and services should be restarted only when their configuration changes. Beta users should keep browsers and operating systems updated and avoid unknown extensions.
Security questions
Use the contact page to report a suspected issue without including wallet seeds, private keys, passwords, access tokens, or provider URLs. No claim of a completed third-party audit or certification is made.