Hardware-backed storage
The key is generated on the device and kept in the iOS Keychain or Android StrongBox. It is never sent anywhere — not in logs, not in crash reports, not in analytics.
Security
Non-custodial is easy to claim and harder to build. This page is the specific version: where the key lives, what a passkey can and cannot do, and the one property that decides all of it.
The line that decides everything
If any flow let us rebuild the ability to sign without your current device — an email reset, a share we hold, a support procedure — then we would have operational control of your funds, whatever the marketing said. So no such flow exists. Encrypted backups go into your own cloud, under a key derived on your device that never reaches us.
The honest consequence, stated before your funds arrive rather than after an incident: lose both your recovery phrase and your backup secret, and nobody can restore access. Not you, not us, not support.
The key is generated on the device and kept in the iOS Keychain or Android StrongBox. It is never sent anywhere — not in logs, not in crash reports, not in analytics.
Face ID or Touch ID unlocks the key for one signature at a time. The signing screen always shows recipient, amount, network and cost — there is no one-tap path for an address you have never paid.
The web app and the Telegram mini app start watch-only — no key exists until you bring one in from Settings. From then on the key stays encrypted at rest, unlocked separately from your session, and once sending from the browser ships, the same rules apply there as on the phone: a large amount, a new recipient or a new device needs a confirmation on your phone.
Recipients are checked against the public EU and OFAC sanctions lists before a transaction is prepared. On a hit we do not prepare it and do not broadcast it — we cannot freeze anything, so declining to assist is the only lever, and it is a written procedure rather than an improvisation.
A detail worth the paragraph
WebAuthn signs with P-256. Tron accounts are secp256k1 and TON is Ed25519, and neither network verifies P-256 for an ordinary account. So a passkey can open your session and, on the web, unlock a keystore already living there — it cannot itself be the key that moves funds on these chains.
| WebAuthn / passkey | P-256 · secp256r1 |
|---|---|
| Tron | secp256k1 |
| TON | Ed25519 |
This matters when comparing products. Anything advertising "a passkey and no seed phrase" on these networks is duplicating key material somewhere, and in practice that means a share held on a server. That is a different claim from ours, and the difference is exactly the recovery path above.
Onboarding
The wallet is created and can receive within seconds, with no twenty-four words to copy down first. Backup becomes a blocking step before your first outgoing transfer, and the state in between — funds present, no backup yet — is visible and warned about rather than quietly tolerated.
Manual recovery-phrase export stays available in settings, always, and is never the only path.
If you are the person who has to sign off on this internally, come and ask them directly.
Talk to us on Telegram