UTXOSUITE — home
LEGAL / PRODUCT NOTICES

Clear boundaries before formal terms.

This page describes the current UTXO Suite product model and privacy/security boundaries. It is not a substitute for transaction-specific, store-specific or entity-specific commercial terms where those are legally required.

§ 01

Scope of this notice

UTXO Suite currently presents transaction-security surfaces including SafeSign, Security Core, Academy and integration work around Guard, Wallet and Relay. Research, prototypes, sibling systems and legacy experiments are not automatically covered as released commercial products by this page.

§ 02

Privacy model

The intended architecture is data-minimizing and local-first where practical. SafeSign and Security Core do not need seed phrases or private-key custody to explain a request. Integrations should avoid collecting full wallet history, raw signatures or unnecessary browsing activity. Any future hosted service that collects personal data must publish its actual controller, purpose, retention period and subprocessors before collection.

§ 03

Security notice

Security analysis reduces uncertainty; it does not eliminate risk. SafeSign, Security Core, Guard or educational material must not be interpreted as a guarantee that a transaction, dApp, address or contract is safe. Missing evidence must be shown as uncertainty rather than silently treated as approval.

§ 04

Non-custodial boundary

The product model does not require server-side custody of seed phrases or private keys, and it rejects automatic signing or automatic broadcast as a default transaction-security behavior. The user or calling wallet remains the authorization boundary.

§ 05

Implementation status

Public UI, source scaffolds, prototypes and production deployments are different states. A page or commit does not by itself prove release, audit, peer review or production readiness. Status should be read from the specific product surface and supporting evidence.

§ 06

Commercial terms

Before paid subscriptions, paid downloads or regulated payment services are offered, the applicable seller/provider identity, price, taxes, cancellation/refund rights, governing terms and consumer disclosures must be published for that exact offer. This page intentionally does not invent those facts.

§ 07

User rights & contact

Where personal data is processed, applicable privacy rights depend on the actual controller and jurisdiction. The production service should publish a verified privacy/security contact and controller information before collecting account or billing data.

Last revised: 26 August 2026 · transaction-security development track

SECURITY & LEGAL BOUNDARY

Security analysis is not custody, signing or a guarantee of outcome.

The legal surface must mirror the technical boundary: explain what is analyzed, what is not controlled, what uncertainty remains and when separate commercial terms are required.

01

NO CUSTODY

Describe what the request can authorize: transfer, allowance, operator rights, typed-data authority or Bitcoin outputs.

method · spender · scope · outputs
02

NO EXECUTION GUARANTEE

Unknown implementation, stale context or unavailable simulation remains visible and can raise REVIEW instead of becoming an implicit allow.

unknowns · freshness · contradictions
03

UNCERTAINTY

Analysis must not require seeds or private keys and must never silently become signing authority.

no seed · no key custody · no auto-sign
04

COMMERCIAL TERMS

Released, audited, peer-reviewed and production-ready are evidence claims, not marketing adjectives.

artifact · test · review · operations
PRODUCT TRUST LOOPTechnical limits and public terms must describe the same product.
  1. 01REQUEST
  2. 02ANALYSIS
  3. 03DISCLOSURE
  4. 04USER DECISION
  5. 05EXTERNAL EXECUTION