ASCELD

Security

Your keys stay yours. By design.

In a financial product, trust is the whole game. Asceld is built so the agent can do the work for you — but can never take your funds. Here's exactly how that holds up.

Non-custodial by architecture

Non-custody isn't a setting we can toggle off — it's how the system is built from the ground up.

We never touch your keys

You connect a wallet you already control. Asceld never asks for, stores, or transmits your private keys or seed phrase.

Enclave signing via Lit Protocol

Operations are signed inside Lit Protocol's secure enclave — hardware-isolated key infrastructure. The signing key is never exposed to Asceld's servers, and the enclave enforces its own destination allowlist per chain.

The agent can't withdraw to itself

The agent is authorized to act on your strategy, not to move funds to an address it controls. There is no path for it to run off with your capital.

Safety rails, enforced before every signature

Autonomy without guardrails is recklessness. These rails are hardened on mainnet and run on every cycle — not in a demo.

Spending caps

A daily ceiling bounds how much capital the agent can deploy, capping exposure even in unexpected conditions.

Reserve floors

The agent keeps a protective reserve untouched, so it can never deploy your entire balance into a position.

Pre-signing checks

Every candidate action is validated against your limits and current conditions before anything is signed.

Whitelisted destinations

Funds can only move to approved destinations — arbitrary withdrawals are not part of the agent's authority.

Emergency pause

A kill-switch halts all agent execution instantly. You can pause — or withdraw — at any time, no permission needed.

Auto-recovery

Safeguards detect abnormal states and stand down rather than push forward. Protecting capital takes priority over acting.

PIN on withdrawals

Moving funds out of the vault requires a PIN only you know, verified server-side — a compromised browser session alone can't cash out.

Defense watch

Every cycle, the agent re-checks position health and stablecoin pegs, and raises the alarm the moment something drifts toward danger.

Decision journal & safety grades

Every run is logged with what the agent did and why, and the app grades your portfolio's safety posture — so trust is inspectable, not assumed.

We describe what each safeguard protects against — the exact thresholds and internal logic stay private, because publishing the precise parameters would help an adversary game them.

How a transaction gets signed

Every on-chain action passes the same gauntlet before it touches the network.

01

Propose

The agent reads market signals and proposes a candidate action for your strategy.

02

Check

The action is validated against your spend caps, reserve floors, and whitelist before it can proceed.

03

Sign

Only if every check passes is the transaction signed inside Lit Protocol's secure enclave — which independently re-checks the destination allowlist before signing.

04

Settle

The signed transaction settles on-chain — publicly verifiable, attributable to your wallet.

Verifiable, not just claimed

Every action the agent takes settles on a public ledger. You don't have to take our word for performance — it's on-chain and attributable to your own wallet. A track record you can verify is the kind that can't be faked.

Audits & responsible disclosure

Independent third-party security audits are part of our roadmap as the protocol surface grows; today, the non-custodial design means your funds are never under our control to begin with. Found something? Reach out at [email protected] — we welcome responsible disclosure.

Security ≠ guaranteed profit. Safety rails protect against operational failure and misuse — they don't remove market risk. Crypto investments can lose value. Please read the Risk Disclosure.

Launch App