Security

An agent with your money needs limits, not trust.

Steven is built on one idea: you set the rules, the Agent works inside them, and everything it does leaves a record. Here is exactly what that means, mechanism by mechanism.

Approval before execution

The Agent proposes; you decide. A trade or transfer is held as a confirmation with the real amounts on it, and expires on its own if you never answer. Approval is checked on the server — a request that skips the card is refused, not merely hidden.

Spending caps that are actually enforced

Per-trade and daily ceilings live with each Agent and are re-checked at the moment of execution against a live quote, not at the moment you set them. A trade whose value can't be established is refused rather than waved through.

Per-person limits in a shared workspace

Someone can be allowed to trade without being handed the whole treasury. A member's daily ceiling applies on top of each Agent's caps, and is checked independently — an uncapped Agent does not become an uncapped person.

Isolated wallets

Each Agent has its own wallet and its own keys. A mandate you give one Agent is not a key to the others, so a bad instruction is bounded by the wallet it was given to.

A stack per workspace

Every workspace is provisioned its own isolated stack — its own gateway, its own database, its own custody. A team's money never sits inside a member's personal one.

An audit log with names on it

Every trade, transfer, approval, limit change and membership change is recorded with who did it and when. On a wallet several people share, this is the only accountability there is.

Two-person approval on large trades

A workspace can require a second person above a threshold. One rejection ends it whatever the quorum — requiring consensus to stop a trade would be the wrong way round.

Two-factor by default

Every account is created with email two-factor already on. It isn't a setting you have to go and find.

Custody

Where the keys actually live.

There are two places your money can sit, and they are not the same. Being precise about which is which is more useful to you than a single reassuring sentence would be.

The vault is yours. It is a Safe smart account on Ethereum, Arbitrum or Optimism, owned by a passkey generated inside your phone's secure element. That key cannot be exported, cannot be copied, and has never existed on our servers — not encrypted, not briefly, not at all. Every payment out of it is signed on your device, and your device recomputes the transaction hash itself and refuses to sign if what we sent it disagrees. If this company vanished tomorrow, you could move those funds from any Safe interface without us.

The Agent's own wallet is custodial. Each workspace runs an isolated stack, and its Agents' keys are held in that stack's gateway, encrypted with a secret unique to the workspace. Those keys are never written to the platform database and never leave the machine — but we hold them, and you should read that as custody. That is the price of an Agent that can bridge, approve a token and finish a trade without sending you off to sign four things.

You choose the split. Funds can sit in either, and most people keep a working balance with the Agent and the rest in the vault. You can also give the Agent a scoped permission to trade from the vault — limited to named contracts and named functions, with sending tokens and changing owners excluded — and it stays off until you turn it on.

Two things we don't have yet, said plainly rather than left out: Solana wallets are custodial only, with no vault; and recovery today means a second device or a wallet you already hold, not trusted contacts who can help you back in.

If we disappeared. The vault would still be there — it is a Safe smart account on a public chain, and Safe's own app can open it. The Agent's wallet would not: we hold that key, and it dies with us. That is the clearest reason to keep only a working balance with the Agent. What happens if Steven shuts down.

Found something? Tell us.

If you believe you have found a security issue, please report it privately before disclosing it anywhere else. We would much rather hear from you than read about it.

security@steven.finance