✣synais.
Security model

Trust the device, verify the action.

Synais is being designed so critical approvals are understandable on the hardware itself. This page separates current concept goals from claims that still need engineering validation.

Threat model

The product is intended to reduce exposure to compromised browsers, malicious extensions, clipboard replacement, accidental transaction approval, and theft of software-wallet secrets from a general-purpose computer.

It cannot eliminate phishing, coerced approvals, poor backup practices, malicious physical access, or mistakes made after ignoring on-device warnings.

On-device confirmation

The launch goal is for important signing details to be displayed on the hardware before approval, including destination, amount, network and relevant transaction context where technically possible.

Private-key isolation concept

Synais is intended to generate and use private keys inside the hardware boundary instead of exposing them to normal application memory. The exact chip architecture, secure-element choice and certification status have not been announced.

No fake certification claims

This prototype does not claim a specific secure-element model, CC/EAL rating, independent audit, or certification.

Recovery model

Recovery exists so ownership is not dependent on one physical device. Support cannot recover your wallet for you and should never know your recovery secret.

Never type your recovery phrase into a website.

Not this website, not a support chat, not a form, and not an email.

Firmware update policy concept

The target model is signed firmware, explicit version visibility, release notes, user-controlled installation and protections against accidental downgrade. Final policy is still being defined.

Supply-chain and tamper considerations

  • Packaging and device identity should be inspectable before setup.
  • The first-run flow should help users detect unexpected prior initialization.
  • Update and recovery procedures should not depend on trusting an unknown third party.

What Synais cannot protect against

  • Approving a malicious transaction you do not understand.
  • Giving a recovery phrase to another person.
  • Physical coercion or compromised backup storage.
  • Future vulnerabilities that have not yet been discovered.

Vulnerability disclosure

A formal security contact and coordinated disclosure policy will be published before public launch. Until then, do not send sensitive wallet secrets or recovery material through support channels.