Docs

Security model

Self-custodial notes, edge checks, no master viewing key. This is a threat sketch, not an audit.

Status: design. XEROPAY is being built. These pages describe intended behaviour. Nothing here is claimed as live mainnet. Details can change. See What's live.

In scope (design)

  • A third party with an explorer cannot read your balance, positions, or counterparties.
  • XEROPAY cannot move funds or decrypt notes.
  • A viewing-key holder cannot spend or widen their own scope.
  • Double-spends are rejected via nullifiers.
  • Sanctioned flow can be refused at the edge.

Out of scope / residual

  • A compromised device that holds the spending key.
  • A guardian set you chose poorly.
  • Side channels at the edge (you still interact with ramps that see fiat identity).
  • Bugs in unreleased circuits and contracts — there is no audit report to link.
  • Network-level metadata of who talked to a relayer, until that is designed away.

Device controls

Per-device limits, freeze, and a kill switch are how a stolen phone is not an unbounded drain. They do not replace key hygiene.