Skip to content
BackSecurity
Security architecture

Chainless has no access to your money.

Every digital holding has a private key, and it works like the title deed: whoever holds the key controls the assets. That is where sovereignty over your own wealth comes from. Chainless does not hold yours. This page shows how your key is created, where it is kept and what happens when something goes wrong.

the key assembles here

5/9

servers confirm
the other four aren't needed

No server holds the whole key. Chainless holds no piece of it.

In numbers

0

pieces of your key held by Chainless

not one

5 of 9

independent servers to release the key

none holds the whole key

1

phone where it comes together

yours

The private key

Whoever holds the private key controls the wealth.

A private key is a secret sequence that authorises moving the assets at an address. It is what proves ownership.

At the exchangethird-party custody
Bitcoin0.84 BTC
where it sitsin their wallet, pooled with everyone else's
who holds the keythey do
how you prove itby asking for a statement

You hold a balance on a screen and a contract.

At Chainlessself-custody
Bitcoin0.84 BTC
where it sits0x7A3…9F2
who holds the keyyou do
how you prove itby reading the blockchain, asking no one

You hold the asset, at an address only your key can move.

It is the same amount in both columns. The difference shows up the day you want to withdraw and someone has to approve it. That is how FTX, Celsius and BlockFi locked up the money of millions of customers.

How it works

The life of your key, from first sign-in to the way out.

Six moments, and in none of them does the whole key exist on a server.

On your first sign-in, nine independent servers each create one piece of the key, and none of them ever assembles the whole key. When you sign in with Google or Apple, every server verifies your sign-in on its own, and the pieces are released only when five of the nine agree. They come together inside your phone, where the key is sealed by the security chip, and only your biometrics unlock it for each signature.
Recovery

And if you lose access?

Losing your phone does not lock you out. But there is one thing to do beforehand, and it takes two minutes.

The phone

stolen, broken or replaced

Sign in on the new phone with the same account and the key assembles there. The balance was never on the old phone: it is on the blockchain.

Your Google or Apple account

minutes

The app

uninstalled or locked out

Reinstall and sign in. Nothing that matters lives inside it, because the app is only the door to your account.

Your Google or Apple account

minutes

The Google or Apple account

lost or locked

Recover the account with Google or Apple themselves, and wallet access returns with it. It is the same sign-in the network verifies.

The provider's recovery

up to them

All of it at once

or Chainless itself

Import the 12 words you exported into any wallet, on any network. It depends on neither Chainless, nor the servers, nor any login.

The 12 words you exported

immediate

Do this today

Export your seed phrase and store it offline.

Two taps in the app's settings. It is 12 words: keep them off the internet, on paper stored somewhere safe, in a vault, or in a password manager only you open. It is path 04, the only one that depends on nobody.

Not even Chainless support can restore your wallet without your sign-in or your key. It is the same property that stops anyone else from touching what is yours.

The worst case

And if it goes wrong?

The seven questions we would ask before putting money in here, answered by the mechanism that prevents each case.

What if Chainless goes under tomorrow?

Your assets are not at Chainless. They are at public addresses on the blockchain that only your key can move. You export the key and carry on from any other wallet. There is no creditor queue, because you were never a creditor.

What if Chainless's servers are breached?

There's no key and no piece of a key to take, and no custodied balance to transfer. A successful attack takes down the interface: the screens stop, your money doesn't.

What if a court orders your wallet frozen?

Chainless can be forced to stop serving you. Freezing or moving what is in your wallet it cannot do, because that technical capability does not exist on its side.

What if someone on the inside wants at your money?

There is no master key, no admin account and no approval queue that signs on your behalf. The signature leaves your phone, with your biometrics.

What if your phone is stolen?

The key is sealed by the security chip and every signature requires your biometrics. Holding the phone without your face, a thief signs nothing.

What if five of the nine servers go down?

Five is the minimum to release, so the network absorbs four servers being down without you noticing. If more than four fail at once, sign-in stops reconstituting the key until they are back. That is exactly the day the key you exported is for.

What if you simply want to leave?

Send to any external wallet, on whichever network you prefer, or export the key and take everything. There's no permission to request, no waiting period and no screen designed to hold you.

Partners

The names holding up each part.

Security that rests on our word alone is not security. These are the companies, networks and rules behind each piece.

Login and key infrastructure
Web3AuthbyMetaMask

today MetaMask Embedded Wallets, after the Consensys acquisition in 2025

The server network that creates and releases the pieces of your key belongs to Consensys, the company behind MetaMask. It acquired that infrastructure so that nobody needs a seed phrase just to open a wallet. It is a third-party component, with public documentation and independent audits.

In their trust center
  • SOC 2
  • GDPR · CCPA · CPRA
  • Penetration test
  • Legal opinion on non-custody
  • Security prospectus
Open the trust center

These certifications and reports belong to the sign-in infrastructure provider, not to Chainless, which none of them audit. They are here because part of your security depends on that provider, and because you can verify them directly with it.

The phone

Apple and Google

The key is sealed by the phone's own security chip. The company that designs and defends that hardware is the device maker.

Secure Enclave · StrongBox

The stocks

Ondo and Ankura Trust

Every tokenized share corresponds to a real share in regulated U.S. custody, under a separate issuer protected in the event of bankruptcy. Ankura Trust verifies that backing every day.

1:1 backing · verified daily

The gold

Paxos and Tether

PAXG and XAUT represent physical gold held in LBMA-standard vaults, with monthly audits of the backing. One token, one troy ounce.

LBMA standard · monthly audit

The dollar

Circle and Ondo

The dollar in your wallet is USDC, from Circle. Dollar yield comes from USDY, backed by U.S. Treasury bills.

USDC · USDY

The protocols

Aave, Uniswap, Curve

Crypto-to-crypto operations run on open, audited, public-code protocols. Anyone can inspect that code at any time.

Open source · onchain

The networks

Bitcoin, Ethereum, Solana

Your assets live on public blockchains. Anyone can check your address and your balance at any time, without asking anyone for access.

Verifiable by anyone

§

The framing

BCB Resolution 520/2025

Chainless operates as a technology provider (art. 9, §6): it doesn't custody, doesn't intermediate and isn't a party to the transactions. Conversions in reais are executed by a partner authorized by Brazil's central bank.

Read the framing

The hard questions

If yours isn't here, there are real people answering in the app.

So what does Chainless keep about me?

Account and app-usage data, plus whatever the regulated partner needs to execute conversions in reais. All of it is described in the Privacy Policy. What does not exist on our side is a key, a piece of a key, any power to move your wallet, or a record of your onchain activity.

Are you regulated by Brazil's central bank?

Chainless is not an institution authorized by the central bank, and couldn't be, because it neither custodies nor intermediates. It is the contracted technology, under art. 9, §6 of BCB Resolution 520/2025. Conversions between reais and crypto are executed by a BCB-authorized partner, which also handles tax reporting for those operations.

Is this safer than a hardware wallet?

They are different models. With a hardware wallet, access depends on one device and one paper backup, and losing both means losing the wallet. Here the day to day does not depend on those objects: access runs through your account, the confirmation of five of the nine servers, and your phone's chip. The seed phrase exists and you can export it whenever you want. It serves as an emergency exit, outside daily use. If you prefer the hardware wallet, export the 12 words and take them, because the path is open and documented.

Do you report my transactions to the tax authority?

Chainless doesn't report balances or onchain activity, because it simply doesn't hold that data. Conversions between reais and crypto are reported by the regulated partners that execute them, under Brazilian rule IN RFB 1.888/2019. In DeFi, the filing is the asset holder's own.

Do I have to trust you for anything?

Yes: the app you install, the screens, the address it shows you when you send, and the code we publish. That is exactly why the way out exists and is documented. You export the key and verify everything in any wallet or block explorer, without us in the loop.

Your part

What the architecture doesn't solve

Self-custody hands control back, and control comes with tasks that are yours.

  • 01Blockchain transactions cannot be reversed. A wrong address, the wrong network, or a scam you confirmed with your own biometrics means money gone. Check before you sign.
  • 02Self-custody has no deposit insurance, and digital assets really do swing. DeFi protocols are audited, but they're still code: smart-contract failure is a real risk.
  • 03Blockchains are public by nature, and anyone who finds your address can read its history. That's the technology, not Chainless.

Chainless is a product of Notus Labs Ltda. (CNPJ 41.212.785/0001-43), a technology provider under art. 9, §6 of BCB Resolution 520/2025. It is not an institution authorized by the Central Bank of Brazil, does not custody virtual assets and has no access to users' private keys. Digital assets carry market risk.

An open vault door, lit from within

Security you can verify, not believe.

Download the app and start in minutes, with Pix.