Seedless
How it works What you can do Fees FAQ
Get early access

Legal

Security Policy

Last updated: 14 September 2026

Seedless is a non-custodial money app on Solana, live on mainnet. People hold their own funds in it. A bug here can cost someone real money, so security reports are the highest-priority work we do.

If you are here to report something, start with section 1.

1. Reporting a vulnerability

Do not open a public GitHub issue for a security problem, and do not post it on X, Telegram or Discord. Report it privately:

ChannelAddress
Emailfrancis@seedlesslabs.xyz
Direct message@francis_codex on X

Include as much of this as you have:

  • what the issue is, and the impact you believe it has
  • steps to reproduce, or a proof of concept
  • the build or commit you tested against
  • whether it affects mainnet, devnet, or both
  • a transaction signature, if there is one
  • how you would like to be credited, or that you would rather stay anonymous

You do not need a polished write-up. A rough report of a real issue is worth far more than a well-formatted non-issue.

Our response commitment

SeverityAcknowledged withinAssessment and fix plan within
Critical24 hours72 hours
High48 hours5 days
Medium72 hours10 days
Low / informational5 daysWith the next release

We will keep you updated while a fix is in progress, tell you when it ships, and credit you in the release notes unless you ask us not to.

2. What this policy covers

Seedless is built partnership-first. Most of the load-bearing cryptography and infrastructure is delegated to external systems with their own audits. Seedless orchestrates audited infrastructure. Seedless itself has not been audited. Our own surface is deliberately small: the app, our payouts service, and one on-chain Rust program.

In scope: report these to us

AreaWhat it covers
Transaction constructionInstruction assembly, token account creation, fee and rent accounting, mint validation, sponsored and unsponsored paths
Session keysStorage, scope, expiry and revocation of session keys used for fast sends
Bank payoutsThe in-app payout flow and our payouts service: authentication, quote and order handling, account-name confirmation, and anything that could send a payout to the wrong account
Private sends and linksOur integration with Umbra: private balances, private sends to people who are not on private mode, link format and collection, take-back, and the gas pool that funds them
ZK proof integrationOur bindings around partner circuits: proof input integrity and handling of secret material during proof generation
On-chain authorization programThe Rust (Pinocchio) controller that gates MPC dWallet operations behind passkey authorization: signature verification, account validation, CPI safety, replay resistance
Money screensCorrectness of send, swap, stocks, earn and payout screens, double-send prevention, and honest disclosure of costs
Stealth addresses and token detectionAddress derivation correctness, and any false token display that could enable phishing
Anything that moves money without informed consentAlways in scope, wherever it lives

Out of scope: report these to the owning project

These are maintained and audited by others. If a report reaches us first, we will forward it and help coordinate.

SystemOwns
LazorKitPasskey authentication, the smart account program, and the integrated Kora paymaster that sponsors fees
UmbraThe privacy protocol, its encrypted execution layer and the ZK circuits themselves
JupiterSwap routing and the lending protocol behind earn
Our payments partnerBank payouts and identity verification on their side
AlchemyRPC infrastructure
IkaThe MPC network protocol and its SDK

Also outside this policy: app store policy questions, and visual issues with no security consequence. Those are welcome as normal issues.

3. Trust boundaries

BoundaryTrust assumption
Passkey signingDelegated to LazorKit. Seedless does not implement WebAuthn or smart-account signing
Network-fee sponsorshipDelegated to LazorKit's integrated Kora paymaster
Privacy protocolDelegated to Umbra. Seedless wraps the client SDK
Swap routing and earnDelegated to Jupiter
Bank payoutsDelegated to a licensed payments partner. Seedless builds the order and confirms the account name
RPCDelegated to Alchemy
MPC and cross-chainDelegated to Ika. Seedless authorizes operations through its own on-chain controller
Transaction construction, session keys, payout orders, private parcels, gas poolImplemented by Seedless
Cross-chain authorization via the on-chain controllerImplemented by Seedless

The last two rows are ours. That is where we most want your attention.

4. Threat model

Assets we protect

  • People's funds: USDC, SOL, tokenized stocks and other tokens held in their smart account
  • Private balances, and the keys behind burner addresses and links that have not been collected
  • Session keys, within their lifetime
  • Payout details held by our payouts service
  • Passkeys, held by the operating system and referenced through WebAuthn, never readable by our code

Adversaries we consider

  • Malicious recipients, including addresses crafted to exploit account-creation flows
  • Anyone who intercepts or guesses a money link
  • Network-position attackers, partly mitigated by HTTPS to every endpoint
  • Malicious apps or sites sending deep links into Seedless
  • Compromised device storage, with limited mitigation because passkeys stay with the operating system

Known gaps

We would rather state these than have you spend time discovering them:

  • Automated tests do not reach real money paths. The logic is unit-tested, including session keys, private-send sequencing, link parsing and amount handling. The paths that move real money (swaps, private sends and bank payouts) are also run by hand on mainnet with a real device, because only that proves them.
  • Parts of the code grew quickly through a hackathon period, and consolidation is ongoing.
  • The on-chain controller is deployed to devnet and has not had a mainnet hardening pass.
  • Not audited. Seedless orchestrates audited infrastructure. Seedless itself has not been audited. That is part of why this policy exists: we would rather hear from you first.

5. Coordinated disclosure

  • No public disclosure of a finding, at any severity, until it is fixed and the fix is confirmed, or until a date we agree together.
  • We aim to fix critical findings within 7 days and high findings within 30. If it will take longer, we will tell you why.
  • If a finding affects a partner, we will coordinate with that partner and keep you in the loop. We will not disclose to a partner on your behalf without telling you first.
  • We are happy to co-publish a write-up after a fix ships.
  • If we go quiet for more than two weeks without explanation, treat that as our failure and escalate by DM.

6. Safe harbour

We will not take legal action, or ask a platform to act against you, for security research done in good faith under this policy. Good faith means:

  • you avoid privacy violations, data destruction and service degradation
  • you do not access or keep other people's data beyond the minimum needed to show the issue
  • you never move funds that are not yours
  • you test on devnet wherever the issue can be shown there
  • you give us reasonable time to fix it before disclosing

Testing against production, the paymaster, the payouts service or any partner system needs our written consent first. Ask. We will usually say yes and help you do it safely.

7. Rewards

Seedless is bootstrapped, so we cannot promise a cash bounty yet, and we would rather say that plainly than imply one. What we can offer today:

  • public credit in the release notes, if you want it
  • a written reference for the work
  • early access, and direct contact with the engineering lead
  • first call on a paid bug bounty programme when one is funded

If you find something critical, talk to us anyway.

8. Supported versions

Only the latest published version of the app receives security fixes. Older builds are not patched and should be updated.

9. Things we will never do

So you can spot someone pretending to be us:

  • We will never ask for a seed phrase. Seedless does not use one.
  • We will never ask for your passkey, private keys or phone PIN.
  • We will never ask you to send us a money link, or to send money to "verify" your account.
  • We will never message you first asking you to connect, sign or "migrate" anything.
  • We will never ask you to install Seedless from anywhere other than our official channels.

Report impersonation to the addresses in section 1.

Seedless

The money app for people who get paid in dollars.

Product

  • How it works
  • What you can do
  • Fees
  • FAQ

Company

  • Support
  • X
  • Telegram
  • GitHub

Legal

  • Terms
  • Privacy
  • Security
  • Data deletion
© 2026 Seedless Labs, Inc. & Seedless Labs LimitedSeedless is a financial technology app, not a bank.