> For the complete documentation index, see [llms.txt](https://docs.redacted.money/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.redacted.money/using-redacted/stay-safe.md).

# Stay Safe

Redacted is built so that very little can go wrong on our side. No server, database or operator can touch your funds, because every action is authorized by a zero-knowledge proof that only your keys can create, and the contract verifies it on-chain every time. If our entire infrastructure disappeared tomorrow, your funds would still be yours and could be recovered directly from the chain.

Your safety therefore depends on a short list of things that only you control.

## The one signature that matters

Your Redacted keys are bound to the private key of your public wallet, so there is no separate secret to manage. Your wallet signs one fixed message, and that signature, which only your wallet's private key can produce, becomes the root of your private account. The signature is free, costs no gas and never leaves your device as a transaction, but it is your master key, and anyone who gets your wallet to produce it can access your private balance.

* Sign the key-creation message only in the official Redacted app. Bookmark it and verify links through the official channels, which are [redacted.money](https://www.redacted.money), [rujira.network](https://rujira.network) and [thorchain.org](https://thorchain.org).
* The message is readable and recognizable. It begins with "Sign in to Redacted", states that it sends no transaction and charges no fee, and names the network, the Redacted contract and your wallet. Read it before you confirm, and if any site shows you this message and it isn't the Redacted app you opened yourself, walk away.
* No one will ever ask you to "sign to verify your wallet", whether that is us, support or an airdrop. A site that asks for a signature it doesn't need is asking for your keys.
* Treat that signature like a seed phrase. Another person, site or app never needs it, and signing it only in the app you opened yourself is the habit that keeps your account yours alone.

Your keys are bound to the Redacted contract and not to a website, so no domain owns your account. If the app ever moves or a frontend disappears, your account is untouched. The matching habit on your side is to read the message you are asked to sign.

## Your wallet is the foundation

Redacted adds no new attack surface to your life. There is no extra seed phrase to store, no server account to breach and no new secret that didn't exist before, so your security perimeter stays the one you already run, which is your wallet and your device.

The usual habits therefore do most of the work. Keep your seed phrase offline, use a hardware wallet and keep your browser and extensions clean. A clean device protects everything on it, including your public wallets and exchanges as well as an unlocked Redacted session, and Redacted inherits the strength of the wallet that creates it.

Hardware-wallet users should know that the device confirms your public transactions, but a private session, once unlocked, acts without it, which is what makes the experience smooth. Lock your session when you're done. Unlocking again takes one confirmation on your device, and that confirmation is what guards your session.

## The backup

Your keys are bound to your wallet's signature, and wallet apps sign in their own ways, so the same seed phrase in a different wallet app can produce a different signature and with it a different account. Keep using the wallet you signed up with.

The encrypted Redacted backup removes that dependency. It stores your private account's root key itself, sealed under your passphrase, so any supported wallet can reopen your exact account with the same balances, positions and identity. Save it once, store the file and the passphrase separately, and no wallet app, device or provider is a single point of failure. Do it right after your first sign-in, and you will find the steps in [Backup and recovery](/using-redacted/backup-and-recovery.md).

## Habits that keep you private

Your privacy depends partly on the crowd you blend into, so the better everyone blends, the stronger everyone's privacy.

* Let deposits rest in the Reserve before moving them to Spending, because time in the Reserve is privacy earned.
* Move different amounts than you deposited, since exact matches are easy to guess.
* Your Spending account trades in public like any account, and its strength is that nothing connects it to you. Fund it patiently and it stays that way.

## Open the real app

Your keys are derived in your browser, so make sure the app you open is the real one.

* Open Redacted from your own bookmark, or from the link published on the official channels. Don't open it from a link in a direct message, an ad or a search result.

{% hint style="info" %}
**Coming soon.** A pinned, verifiable app version is an upcoming step before the node network launches. It will be a fixed version with a fixed content hash, which is a fingerprint of the app's files, so you can check that the app you opened is exactly the one we published.
{% endhint %}

## Use a clean browser

While your session is unlocked, your keys live in your browser, so keep that browser clean.

* Make a separate browser profile just for Redacted, with no extensions except your wallet. An extension that can read all pages can read what the app shows, including your balances, positions and activity.
* Keep your browser and your device's operating system up to date.

## Sign in safely

* Use a hardware wallet to sign in if you can. Your seed phrase stays on the device, and every unlock needs your confirmation on it.
* Lock your private session when you are done. An unlocked session acts without asking your wallet again, and it locks itself after 15 minutes without activity (see [Sessions](/using-redacted/sessions.md)).
* Never sign the Redacted sign-in message on another site. It begins with "Sign in to Redacted" and belongs only in the app you opened yourself. See [The one signature that matters](#the-one-signature-that-matters).
* Add a passkey on each device you use for Redacted. Turn on **Passkey for withdrawals and sends** and set **Passkey at unlock** to **Passkey and wallet** for the most protection. Your passkey then joins your wallet at every unlock, and the app asks for it again before money leaves (see [Passkeys](/using-redacted/sessions.md#passkeys)).

{% hint style="info" %}
**Coming soon.** Passkeys arrive with the launch, so you can add this layer from day one.
{% endhint %}

## Keep a backup, offline

Save the encrypted backup once, as described in [Backup and recovery](/using-redacted/backup-and-recovery.md), and keep the file offline, for example on a USB drive.

* Use a strong passphrase, or let the app generate one.
* The safest place for the passphrase is offline too, for example on paper, in a different place from the file.
* The backup file plus its passphrase is full control of your account, so treat the pair like a seed phrase and share neither.

## Split savings from daily use

Your private account comes from your wallet, so a different wallet gives you a separate account.

* Keep your savings in a second private account, made from a different wallet with its own seed phrase. Open it rarely, and only from a clean device.
* Use a separate account for daily trading, and keep only what you need in it.

## Watch amounts and timing

Amounts and timing are public on-chain, and they are how an observer would try to link a deposit to what you do next. Withdraw a different amount than you deposited, and give money a moment before you use it. With the node network, new money also waits about two hours before it can be used privately.

See [Why new money waits](/using-redacted/privacy.md#why-new-money-waits) for the wait and [How to get the strongest privacy](/using-redacted/privacy.md#how-to-get-the-strongest-privacy) for amounts.

## If you suspect a compromise

Act fast, from a clean device if you can. Moving your money out first puts it back in your control while you work out what happened.

* If your private account may be exposed, for example because you signed the Redacted message on another site or your backup and passphrase leaked, withdraw everything to your wallet or move it into a new private account made from a different wallet, and then stop using the old account.
* If your wallet itself may be compromised, move the funds from your private account to a fresh wallet you control. Your backup lets you do this without touching the old wallet again (see [Withdraw after restoring](/using-redacted/backup-and-recovery.md#withdraw-after-restoring)), and afterwards you should stop using the old wallet.

{% hint style="info" %}
**Coming soon.** Home-wallet rescue will bind your account to your own wallet from day one, and an upgrade will let money always find its way home during an incident. See the [Roadmap](/project/roadmap.md#next-up).
{% endhint %}

## The short version

1. The key-creation signature is a seed phrase. Sign it only in the official app.
2. Guard your wallet like always, because Redacted inherits its safety.
3. Save the encrypted backup once, which makes your account independent of any wallet app.
4. Lock your session on shared or risky machines.
5. Wait, then move different amounts, and the app guides you.
