Trust & threat model
Security at Riddle
We optimize for self-custody and transparent production behavior — not demo shortcuts.
No server seeds
Wallet private keys are not stored as server-side custody. Encrypted material lives on the client; you control PIN and device.
User-signed XRPL
Swap, Bridge, Cafe, Creator flows present Xaman payloads you must approve. Never sign blind QR codes from untrusted sites.
Production payments
Subscription activation in production requires real payment evidence. Demo activate and stub PAYG credits are disabled in production.
Empty ads ≠ fake ads
When no campaign is booked, AdSlots stay empty. We do not invent mock sponsors in production UIs.
What you must protect
- Seed phrases and private keys (never share; never paste into random forms)
- PIN / device access to the vault
- Phishing domains — only use *.riddlewallet.com
- Payload details in Xaman (destination, amount, currency/issuer)
What we operate
- Static/marketing hub and product frontends
- Proxies, quotes, marketing/ads APIs, broker helpers
- Treasury addresses for legitimate suite fees and tiers
What we do not do
- Recover lost seeds
- Reverse user-signed transactions
- Guarantee third-party bridge/market outcomes
- Provide financial advice
Report security issues to hello@riddlewallet.com with “Security” in the subject.