Skip to main content

Security · Practices

Checks before every operation

Hosted surfaces raise the work; none of them is where the policy lives.

See technology

Commitments

What must be true before it moves

Four conditions. Where a mechanism page exists, the row opens it — posture here, depth there.

  1. No single actor moves alone

    How this is enforced

    Sensitive operations need more than one party — across time through a waiting period, or across roles, where whoever authorises is not whoever submits.

  2. The interface cannot override the chain

    How this is enforced

    Another client calling the same contracts cannot skip the rules, and compromise of a hosted surface does not grant a bypass.

  3. Evidence stays with the operation

    Who proposed, who approved or cancelled, and what ran is part of chain history rather than a chat log. That is a design property, not a certification — Particle CS holds none.

  4. Recovery without custody

    How this is enforced

    Governed recovery paths can restore control without Particle CS holding keys, and changes to recovery follow the same lifecycle as anything else.

In the product

What enforcement looks like

Roles, waiting work, and the account overview — the same surfaces operators use.

Ask which of these is alpha

Some of these checks are shipped and some are roadmap. Ask, and we will show you where each one runs.

Alpha · Testnet · Personal workspace