Security
Local-first. No backend. Your keys never leave your phone.
Architecture
Untaxed runs entirely on your device. There are no hosted wallets, accounts or backend databases. Everything critical happens locally:
- Private keys and seed phrases are encrypted and stored inside the app's sandbox
- Transactions are built and signed on the phone
- External communication is limited to Solana RPC, Jupiter, Helius, Jito and market-data APIs
- The developer collects no data from the app
Key encryption
- Password derivation: your password runs through PBKDF2 with 100,000 iterations and a random salt.
- Encryption: keys are encrypted with AES-256-GCM using the derived key and a random IV.
- Storage: the encrypted blob, salt and IV are stored on the device. The password is never stored.
- Decryption: unlocking re-derives the key from your password. A wrong password fails decryption.
Why PBKDF2 with 100K iterations? It makes brute-force password guessing computationally expensive even if the encrypted data were ever extracted from a device.
Biometrics & PIN
Biometric unlock (Face ID or Touch ID on iOS, fingerprint or face unlock on Android) uses the device's own authentication. Biometric data stays in the phone's secure hardware and is never available to Untaxed. They gate access to the already-encrypted keys; they do not replace the password that encrypts them.
Memory management
- Sandboxed: iOS and Android prevent other apps from reading Untaxed's memory or storage
- Cleared on lock: auto-lock or manual lock wipes decrypted keys from memory
- Cleared on exit: when the OS terminates the app, keys are gone until you unlock again
Auto-lock
Configurable inactivity timeout, default 15 minutes. When triggered:
- All decrypted keys are deleted from memory.
- The app shows the lock screen.
- Nothing can be signed until you authenticate again.
Transaction signing
- The app builds the transaction for a swap, send or order.
- It is signed with the decrypted key held in memory.
- Only the signed transaction leaves the device, via your selected engine.
- Private keys never leave the app process.
Network communication
- Solana RPC: balance queries, transaction submission, account info
- Jupiter API: quotes, swaps, token search and trigger orders
- Helius API: transaction history, token metadata, Helius Sender and holder verification
- Jito Block Engine: bundle submission when using Jito or Helius Sender
- Market data: trending, pump.fun firehose, DexScreener feed, prices and charts
No private keys or seed phrases are ever sent to any external service. No analytics or telemetry is sent anywhere.
Best practices
- Use a strong, unique password.
- Write down your seed phrase immediately after creating or importing a wallet and store it offline.
- Keep auto-lock at 5 or 15 minutes.
- Never share your password, seed phrase or private keys with anyone, including support.
- Use balance hiding when you're in public or streaming.
- Keep your OS and the app updated.