Research preview · No live network or real fundsProject status ↗
Trust / Security

Clear boundaries
are part of the design.

Useful financial software tells you what it can verify—and what you should not trust it with yet.

A research site, not a financial service.

This public site does not create wallets, accept deposits, connect browser wallets, collect private keys, issue cards or submit transactions. The interactive account view is an in-memory illustration that resets on reload.

Never send funds to an address presented as a 1soft presale or give a seed phrase to someone claiming to activate this project. No such service is offered here.

What the prototypes aim to enforce.

Native rules enforce signature and counter checks, exact consent, bounded recipients, grant expiry and aggregate native spending ceilings. Client-side work separates signing, submission and evidence of execution.

Those controls are under development. Read the working paper for their assumptions and boundaries. “Tested locally” is not equivalent to secure production custody.

What remains unverified.

Actual communicating-validator execution, independent public operation, production key protection, dynamic-validator light-client behavior, independent audit and customer-fund handling remain unverified or unbuilt.

The project does not claim a production throughput rate, guaranteed availability, anonymity, reserve backing, insurance or a completed external security certification.

Keep public and privileged systems apart.

The website is deliberately static. It contains no signer, node administration endpoint or RPC proxy. The future account interface should not share the authority of a validator or reserve custodian.

Private prompts, agent memories, personal biographies and payment-card details do not belong in a public ledger. Compact proofs reduce unnecessary response data; they do not remove every privacy risk.

Responsible disclosure is a launch gate.

A verified private disclosure channel and incident-response process must exist before external testing or public network operation. No monitored security mailbox is being advertised on this preview.

Do not post private keys, customer data or an active vulnerability in a public conversation. This site’s lack of a reporting form is deliberate while those operations are not established.