Security model
Self-custodial notes, edge checks, no master viewing key. This is a threat sketch, not an audit.
Status: design. XEROPAY is being built. These pages describe intended behaviour. Nothing here is claimed as live mainnet. Details can change. See What's live.
In scope (design)
- A third party with an explorer cannot read your balance, positions, or counterparties.
- XEROPAY cannot move funds or decrypt notes.
- A viewing-key holder cannot spend or widen their own scope.
- Double-spends are rejected via nullifiers.
- Sanctioned flow can be refused at the edge.
Out of scope / residual
- A compromised device that holds the spending key.
- A guardian set you chose poorly.
- Side channels at the edge (you still interact with ramps that see fiat identity).
- Bugs in unreleased circuits and contracts — there is no audit report to link.
- Network-level metadata of who talked to a relayer, until that is designed away.
Device controls
Per-device limits, freeze, and a kill switch are how a stolen phone is not an unbounded drain. They do not replace key hygiene.
