§ 01Scope of this notice
UTXO Suite currently presents transaction-security surfaces including SafeSign, Security Core, Academy and integration work around Guard, Wallet and Relay. Research, prototypes, sibling systems and legacy experiments are not automatically covered as released commercial products by this page.
§ 02Privacy model
The intended architecture is data-minimizing and local-first where practical. SafeSign and Security Core do not need seed phrases or private-key custody to explain a request. Integrations should avoid collecting full wallet history, raw signatures or unnecessary browsing activity. Any future hosted service that collects personal data must publish its actual controller, purpose, retention period and subprocessors before collection.
§ 03Security notice
Security analysis reduces uncertainty; it does not eliminate risk. SafeSign, Security Core, Guard or educational material must not be interpreted as a guarantee that a transaction, dApp, address or contract is safe. Missing evidence must be shown as uncertainty rather than silently treated as approval.
§ 04Non-custodial boundary
The product model does not require server-side custody of seed phrases or private keys, and it rejects automatic signing or automatic broadcast as a default transaction-security behavior. The user or calling wallet remains the authorization boundary.
§ 05Implementation status
Public UI, source scaffolds, prototypes and production deployments are different states. A page or commit does not by itself prove release, audit, peer review or production readiness. Status should be read from the specific product surface and supporting evidence.
§ 06Commercial terms
Before paid subscriptions, paid downloads or regulated payment services are offered, the applicable seller/provider identity, price, taxes, cancellation/refund rights, governing terms and consumer disclosures must be published for that exact offer. This page intentionally does not invent those facts.
§ 07User rights & contact
Where personal data is processed, applicable privacy rights depend on the actual controller and jurisdiction. The production service should publish a verified privacy/security contact and controller information before collecting account or billing data.
Last revised: 26 August 2026 · transaction-security development track