Security Architecture
How DexPrime protects your digital assets with bank-grade encryption.
1. Non-Custodial Infrastructure
DexPrime is built as a strictly non-custodial interface. We do not have a centralized server that stores your funds or keys. Unlike a centralized exchange (CEX), we do not hold your assets in our custody.
The Rule of Web3: "Not your keys, not your coins." With DexPrime, you are the only one with the power to access and move your funds.
2. AES-256 Local Encryption
When you create or import a wallet on DexPrime, your Secret Recovery Phrase and Private Keys are encrypted using the AES-256 (Advanced Encryption Standard) algorithm.
- Client-Side Only: All encryption and decryption happen directly on your mobile device.
- No Transmission: Your unencrypted private data is never sent over the internet or stored in a cloud backup.
3. Hardware-Level Protection
DexPrime leverages the hardware security features of modern smartphones to keep your data safe:
iOS Keychain
Utilizes the Secure Enclave on iPhone for tamper-resistant key storage.
Android Keystore
Implements hardware-backed cryptographic operations to prevent unauthorized extraction.
4. Industry Standard Recovery (BIP-39)
We use the BIP-39 standard for generating your 12 or 24-word Secret Recovery Phrase. This means your wallet is fully compatible with other industry-leading wallets like MetaMask, Ledger, and Trust Wallet. You are never "locked-in" to the DexPrime ecosystem.
5. Biometric Authentication
To prevent physical unauthorized access, DexPrime includes multiple layers of authentication:
- Biometrics: Unlock your wallet using FaceID or Fingerprint.
- Secure PIN: A secondary 6-digit PIN is required for confirming all outgoing transactions.
6. Encrypted API & Node Interaction
All communication between the DexPrime app and blockchain RPC nodes is performed over HTTPS/TLS 1.3. This prevents "Man-in-the-Middle" (MITM) attacks and ensures that your transaction requests are broadcasted securely to the network.
7. Audit & Transparency
We believe in the power of "Don't Trust, Verify." Our core security libraries are regularly audited by independent third-party security firms to ensure that no vulnerabilities exist in our encryption logic.
Security Tip: DexPrime will never ask for your recovery phrase. Never share your 12 words with anyone, including our support team.