Self-custodial
Wallet keys are kept on the user device. Ondex does not need seed phrases or private keys to render the website, publish content, or prepare account identity surfaces.
Ondex Security
Ondex is built around a simple custody boundary: wallet control belongs on the user device, not on a marketing site, admin panel, or backend service.
Wallet keys are kept on the user device. Ondex does not need seed phrases or private keys to render the website, publish content, or prepare account identity surfaces.
Transaction approval is designed around device-side signing, so sensitive wallet authorization is separated from public website content and backend draft workflows.
Privacy and communication surfaces are designed to minimize unnecessary exposure while still giving users clear controls and public policy references.
Ondex does not need your recovery phrase, private key, PIN, backup password, or hardware-wallet secret to render public pages, prepare dApp requests, provide support, or operate backend services.
Ondex may process app telemetry, push registration data, support tickets, provider/ramp status, compliance-relevant provider data, public profile data, and public blockchain references where those surfaces are used.
XRPL transaction approval is reviewed in the app and signed on the user's device. Backend services can deliver payloads or notifications, but they do not receive seeds or private keys for signing.
WalletConnect and one-shot payload requests are delivery mechanisms. Ondex validates account, chain, transaction type, fees, memos, expiry, and high-risk operations before signing where supported.
Users are responsible for maintaining access to their self-custodial wallet backup. Ondex support cannot reconstruct a lost recovery phrase or private key.
Public blockchain transactions are irreversible, third-party provider flows can add their own requirements, and public safety signals should not be treated as investment, legal, or formal audit advice.
Ondex is preparing an external audit scope for wallet key storage, unlock and signing flows, payload validation, WalletConnect handling, deep-link sanitization, backup boundaries, and wallet-authenticated backend flows. Public copy will link to a report or scoped summary only after an audit is complete.
Public safety claims should link to this page, the privacy policy, the terms, or product pages. Internal repository paths must stay out of published copy.