Trust model
What you are trusting, in plain English
Private by default does not mean trust nothing. Here is exactly who could do what.
The short version
Sealed cannot move your money. A smart contract, not a company, decides what can be signed for your account, and it has no function that lets us move user funds.
Private is not anonymous. Payments into and out of the private layer are visible on public blockchains. What stays private is who a payment was for, your balance and your activity.
You are still trusting some things: your X account, the network that signs transactions, the secure hardware that checks your sign-in, and the validators that run the private layer. Each is explained below.
What we, the operators, cannot do
- Move your funds. Every signature for your account goes through the vault contract. It only signs when the request comes from approved agent code, and it checks a one-time number (nonce), an expiry time and your limits every time.
- Change the rules quietly. New limits, new agent code and contract upgrades wait in a public 14-day timelock and are announced on-chain before they take effect. The contract can be locked forever, removing upgrades entirely.
- Decline, reverse or claw back a payment. Once money is credited to an @, it belongs to that @. There is no expiry and no return to the sender.
- See your balance. Balances live in the private layer. Reading them needs a signature from your account, which only happens inside your own signed-in session. We never store balances or activity.
- Post on your X account. Sign in with X is read-only. We learn your numeric X ID and public profile, then throw the X token away.
What you are trusting
- Your X account. Whoever can sign in to your X account can open your wallet and, until you add your own key, withdraw (within the limits below). Turn on two-factor authentication on X, and add your own key right after you first sign in.
- X itself. X tells us which account signed in. If X were compromised it could misreport that, which matters only for wallets that have not added their own key.
- The signing network. Addresses come from NEAR Chain Signatures (v1.signer): a group of independent nodes (8 at the time of writing) that sign together without ever assembling a private key in one place. If enough of them colluded, they could sign anything.
- The secure hardware. The agent that checks your sign-in and builds transactions runs inside a trusted execution environment (TEE) and proves which code it runs. The approved code hash is published on the Stats page. A hardware flaw or a compromised hosting provider could let an attacker act as the agent; the contract limits, the delay queue and the circuit breaker cap the damage for wallets still using the system key.
- The private layer. Private balances, transfers and swaps run on NEAR Intents’ confidential environment (the NEAR Private Shard), which is operated by an approved set of validators. If they were compromised, private data could leak.
- Code without bugs. The vault contract and agent have not been audited yet. See the Stats page for audit status.
What is public and what is private
Public (anyone can see)
- Your payment into the private network: wallet, amount, time, on the chain you paid from
- Withdrawals out of the private network: amount, destination, time
- Payments to an @’s public deposit address, and the move into their private balance
- An @’s deposit addresses and whether its owner has opened it
- While the system key still holds an account: the token and amount of each withdrawal, swap or send from its balance
Private (only the owner)
- Who a private payment was for
- The balance of any @
- Incoming private payments to an @
- Swaps and sends from your balance, once you hold your own key
- Your list of past activity
While the system key holds your account, what you move out is public. The vault contract enforces your limits on-chain, so every withdrawal, swap or send from your balance is a public NEAR transaction showing your X ID, the token and the amount. Incoming payments and your balance stay private. Once you add your own key and remove the system key, Sealed is no longer involved and this stops.
When you act is visible. Every signature for your account is requested on NEAR with your numeric X ID in it, so anyone can see when your account signs something, even when they cannot see what.
Timing and amounts can give you away. If you pay 123.45 USDC in and the recipient withdraws 123.45 USDC a minute later, an observer can guess the link. Round amounts and waiting before withdrawing make that much harder.
Protections while the system key is active
- A daily withdrawal limit per asset (about $10,000), stored in the contract.
- Withdrawals above about $2,500 wait 24 hours in a delay queue, and you can cancel them.
- Withdrawals and ownership changes need a sign-in from the last 5 minutes.
- A circuit breaker can pause withdrawals made through the agent if something looks wrong. It can never move funds, and it switches itself off after 72 hours.
Taking full ownership
Once you have signed in, you can add your own key: a passkey on your device or a wallet you control. You can then remove the system key entirely. From that moment only your key can move your money, the limits above no longer apply, and nobody (including us) can recover your funds if you lose your key.
New payments still reach you after you take ownership, and money sent to your public addresses is still moved into your private balance.
If Sealed disappears
Your money sits in your own account in NEAR Intents, not with us. If you added your own key, you can use it with any compatible wallet to move your funds, with or without us.
The agent is stateless and its code is public: anyone can run an approved copy in secure hardware and serve the same accounts. If no agent is running and you have not added your own key, you would have to wait until someone runs one. That is another reason to add your own key.
Contract addresses, the approved agent code hash and audit status are on the Stats page.