Trust & threat model

Security at Riddle

We optimize for self-custody and transparent production behavior — not demo shortcuts.

No server seeds

Wallet private keys are not stored as server-side custody. Encrypted material lives on the client; you control PIN and device.

User-signed XRPL

Swap, Bridge, Cafe, Creator flows present Xaman payloads you must approve. Never sign blind QR codes from untrusted sites.

Production payments

Subscription activation in production requires real payment evidence. Demo activate and stub PAYG credits are disabled in production.

Empty ads ≠ fake ads

When no campaign is booked, AdSlots stay empty. We do not invent mock sponsors in production UIs.

What you must protect

What we operate

What we do not do

Report security issues to hello@riddlewallet.com with “Security” in the subject.