Trust

Security and trust

What your wallet signs, where the keys live and how you can check every action.

Signing in

You sign in with Sign In With Solana. Your wallet signs a readable message tied to this site's domain, and the message states that it does not authorize a token launch. Each sign-in request works once and expires after 5 minutes. A session lasts 12 hours, the server keeps only a hash of it, and signing out revokes it.

What your wallet signs

  • Two kinds of transaction, nothing else: a plain SOL transfer when you fund your agent wallet, and the launch of your own coin. Your wallet previews both before you approve.
  • Withdrawals and fee collections from the agent wallet need your signature on a message naming that exact action: the amount, the destination, the network, the transaction's hash and an expiry 3 minutes out. Each signature works once.
  • A launch builds on your approval of one exact package revision, identified by its manifest hash. If the package changes after you approve it, Orbit refuses to launch it.

Keys and records

  • Agent wallet keys, and the key of each new coin's mint, are encrypted at rest with AES-256-GCM and never leave the server.
  • Every action goes into an append-only, hash-chained ledger: each entry commits to the one before it. Owners can export the whole log and verify it.
  • Every coin page shows its launch transaction and the launch message that was signed, the manifest hash it committed to and the content hashes of its artwork, website and metadata.
  • Coin websites are static pages with no scripts, locked down by a content security policy.