StakeGuard StakeGuardOffline recovery security
Security model

Built around non-custody and offline signing.

StakeGuard messaging should be direct: private keys stay offline, users keep control, and downloads must be verified.

01

Private keys stay offline

The Offline Signer is designed for workflows where sensitive key operations are not performed on the online backend.

02

Non-custodial by design

StakeGuard should not have unilateral control over user Bitcoin.

03

Integrity verification

Users should verify release checksums before installing the Offline Signer.

04

Encrypted recovery data

Recovery data should be encrypted before transport or storage.

05

Clear recovery assumptions

Users should understand who can recover, when recovery is possible, and what transaction is being prepared.

06

Security reporting

Security researchers and users should have a direct route to report issues.

Responsible disclosure

Found a security issue?

Use the support page and choose Security report. Replace this text with your final security policy before public launch.