Protection built in layers
Two-of-three asset ownership, independent transaction checks and an isolated backend for each account work together to protect your wallet. No single asset-owner key can authorize an asset transaction.
Configured spending limits, recipient rules and freeze controls govern server approval. Send Seal adds hardware-key approval for covered high-value payments and security changes. Each control has a defined scope; review the details and limits below.
Two owners protect your assets
Your phone, the Orrerie server and your offline recovery card each hold a separate signing key. A supported asset wallet requires two of those keys to approve a transaction.
Orrerie holds the server key. It cannot move funds with that key alone. Your phone and offline-card recovery words can move funds without it, using the Orrerie Recovery tool and a Recovery kit you exported beforehand.
Your separate Personal Gas phrase controls the EVM gas account and fee-only Solana and
TRON addresses. The keys stay on your phone; Orrerie does not hold your personal fee funds or keys. Your Funding and Spot asset wallets retain their separate two-of-three owners. Paying fees gives a gas key no asset-owner vote.
Check what is being signed
Your phone builds or independently rebuilds the transaction. The server checks the same transaction before adding its signature.
The server also applies freeze settings, spending limits and recipient rules. If a required value or transaction detail cannot be verified, approval stops.
Choose your transaction protection
For supported EVM transactions, Standard protection permits direct transfers and exact swaps or bridges built and simulated by your server. Strict permits direct native or token transfers and permission revocations, while refusing swaps, bridges and other contract calls.
Recent decisions shows whether the server allowed or blocked a signing request, with its reason. Changing the protection rules requires the registered Send Seal security key.
Review token permissions
Token permissions scans supported EVM wallets for detected token allowances. See which contract can spend a token, review the allowance and spot unlimited permissions.
Revoke a permission you no longer need through the usual phone approval and co-signing flow. A revocation is an on-chain transaction and can incur a network fee; the list covers the permissions the scan can detect.
Add Send Seal
Send Seal asks for a registered hardware security key on covered high-value payments and security changes. Its approval is short-lived, works only for the specific action and can be used once.
It adds a separate check beyond unlocking the phone. It still matters to protect your device and recovery material.
Protect messages in transit
Native app requests, responses and live updates are encrypted in addition to HTTPS/TLS. Payme and website enquiries use separate encrypted connections.
Each connection uses ephemeral P-256 ECDH, HKDF-SHA256 with separate send and receive keys, and AES-256-GCM. A P-256 ECDSA/SHA-256 signed manifest authenticates the session setup.
Native app encryption ends at Orrerie’s trusted gateway, where account access is checked. It does not make public browser code secret or protect a compromised device or server.
Separate accounts and signing keys
Each Orrerie account has its own isolated backend, stored data and server co-signer. Account records are encrypted at rest. This separation limits access between accounts; it does not make the service immune to a compromised host.
Email sign-in reconnects your account. Phone and offline recovery words never enter account sync or server backups. PINs, device credentials and biometric security settings are also excluded from account sync.
Know the limits
If an attacker obtains both the phone’s signing key and its server access credential, ordinary co-signing checks can be undermined. Send Seal adds protection for the actions it covers.
No independent audit or security certification is claimed. Software bugs, provider failures and recovery mistakes can still cause loss.
Frequently asked questions
Can one stolen key empty my wallet?
One signing key alone cannot satisfy a supported asset wallet’s two-of-three rule. That does not make every compromise harmless. An attacker who obtains the phone signing key together with its server access credential may undermine ordinary co-signing checks. Protect the whole device and its credentials, and understand which actions Send Seal covers.
What does the server check before signing?
It checks the exact transaction and applies the wallet’s configured rules, including freezes, spending limits and recipient restrictions. The transaction must match what the phone reviewed and be a type the wallet can verify. If a required price or transaction detail cannot be established, the server refuses approval instead of guessing.
What does Send Seal add?
Send Seal uses a registered hardware security key as an extra approval for covered high-value payments and security changes. The approval is tied to the exact action, expires quickly and can be used once. It is separate from unlocking the phone, so a normal app unlock is not enough for an action requiring Send Seal.
Does Face ID change the two-of-three requirement?
No. Face ID helps unlock local access or signing when enabled. Spot can also use a separate PIN. These methods do not lower the number of signatures needed by the wallet, remove server rules or replace Send Seal where it is required. They also do not replace your passphrase and recovery preparations.
Can the gas key spend my Funding or Spot assets?
Your separate Personal Gas phrase controls the EVM gas account and fee-only Solana and
TRON addresses. The keys stay on your phone; Orrerie does not hold your personal fee funds or keys. Your Funding and Spot asset wallets retain their separate two-of-three owners. Paying fees gives a gas key no asset-owner vote.
What is protected by the encrypted website connection?
The enquiry form and Payme encrypt application requests and responses in addition to HTTPS. Native app requests, responses and live updates also use a separate authenticated encrypted channel. Orrerie’s servers process the decrypted information. These controls protect defined messages in transit; they do not hide public browser code or protect a compromised device or server.
Has Orrerie been independently audited?
No independent audit or security certification is claimed on this site. The security pages explain the design and its limits so you can understand what the controls do. Testing and defensive checks do not eliminate software bugs, provider risks or recovery mistakes, and they should not be read as a guarantee against loss.
Can I revoke an existing token approval?
Yes. Open Account → Token permissions to scan supported EVM wallets, inspect detected allowances and review the spending contract. Choose Revoke for a permission you want to remove, then approve the transaction in the app. Revocation can have a network fee. The scan is limited to the permissions it can detect.
What changes when I choose Strict protection?
For supported EVM transactions, Strict allows direct native or token transfers and permission revocations. It refuses swaps, bridges and other contract calls. Standard can allow exact server-built and simulated routes. Both retain the wallet’s ordinary signing requirements; changing the protection rules requires your registered Send Seal security key.
Can I move my funds if Orrerie is offline?
Yes, if you prepared beforehand. The Orrerie Recovery tool, downloaded from recover.orrerie.com, signs with your phone and offline-card recovery words on your own computer and sends transactions through public blockchain endpoints, without Orrerie’s servers. It reads your wallets from a Recovery kit that you export in the app while Orrerie is available; without a kit it can find only EVM Safes. Check the file’s SHA-256 and release key fingerprint before entering any words.
Interested in Orrerie?
Request access