Local signing
Wallet keys are generated or imported on the device. Aura signs transactions locally. Recovery phrases and private keys are not sent to balance or swap providers.
Secure storage is not hardware signing
The mobile app stores encrypted recovery information using platform secure storage. This does not mean arbitrary blockchain keys sign transactions inside the Secure Enclave. Keys can be exported after authentication.
Limits of wallet protection
Device encryption does not make a malicious token, website or signed transaction safe. Check recipients, token contracts and permissions before confirming. Aura cannot reverse a confirmed transfer.
Source reviewed . Live release verification remains separate.