The Aura security model

How keys, device access and public network requests fit together.

Local signing

Wallet keys are generated or imported on the device. Aura signs transactions locally. Recovery phrases and private keys are not sent to balance or swap providers.

Secure storage is not hardware signing

The mobile app stores encrypted recovery information using platform secure storage. This does not mean arbitrary blockchain keys sign transactions inside the Secure Enclave. Keys can be exported after authentication.

Limits of wallet protection

Device encryption does not make a malicious token, website or signed transaction safe. Check recipients, token contracts and permissions before confirming. Aura cannot reverse a confirmed transfer.

Source reviewed . Live release verification remains separate.