Skip to main content

Solutions · Secure applications

Rules your application cannot bypass

Policy sits with the account, so another client cannot talk past your checks.

Instead of — UI rules that are not enforcement

Pre-execution checks in the path

Sensitive actions are validated before they settle — mistakes and unauthorised calls are refused, not cleaned up later.

Instead of — One admin key standing in for an architecture

Open protocol as the foundation

Embed programmable governance — roles, waits, rules for external calls — into the contracts your application already uses.

Instead of — Every team rebuilding the same governance

Composable pieces

Adopt a full governed account or the subsets you need. The SDK and docs are the build path; the Platform is optional.

Instead of — Docs without a policy layer

Same policy operators already run

When a team also uses the Platform, builders and operators share one on-chain policy model.

This covers

  • Governed account infrastructure
  • Embedded governance
  • Developer infrastructure
  • Protocol integrations

Questions

  • Who is allowed to move funds?

    Whoever you name, and only for the operations you name them for. Roles decide who may request, who must wait, who may approve, and who may execute — and the contract refuses an unauthorised call before it reaches your funds, rather than relying on an interface to prevent it.

    Roles and approvals
  • Can someone bypass the rules through the interface?

    No — the interface cannot override policy. The same on-chain rules apply whether the request comes from the Platform, from your own application through the Protocol, or from a script, because enforcement sits in the contract rather than in any of the things asking.

    Pre-execution security
  • What stops a compromised integration from draining an account?

    Each operation type is limited to a list of permitted targets, so a mistyped address or a compromised integration has nowhere to send funds. Automation can hold a role and still be bounded by the same policy as a person — a signing key is not an all-or-nothing grant.

    Automated operations
  • Do we have to use your application?

    No. The Platform runs these operations in the browser; the Protocol builds the same rules into systems you already run. They enforce identically because they enforce in the same place — the contract — so the choice is about where your team works, not about how much control you get.

    Build on the Protocol

Build on rules you did not have to invent

Protocol in your own systems, or Platform in the browser.

Alpha · Testnet · Personal workspace

Read SDK guides (opens in a new tab)