◆ Security & Trust

You keep your keys.
We never hold them.

Autonomous Intelligence is non-custodial by design. The platform never holds your funds, never signs a transaction on your behalf, and your private key never leaves your wallet. This page states exactly what that means and how to report a vulnerability.

01 · Custody model

Non-custodial, end to end

A swap on Autonomous Intelligence is built by the server, signed by you, and broadcast only after you sign. There is no deposit account, no custodial wallet, and no balance the platform can move on your behalf.

What this means in practice

If our infrastructure were fully compromised tomorrow, your funds would still be in your wallet. We cannot move them, because we never had them.

02 · Access & keys

API keys are scoped, not custodial

Access to the agent rail is controlled by an API key you create. Read-only tools (quote, safety, discovery, token info) work without a key; key-gated tools (build_swap, submit_swap) require it.

Read tools are open

Quote, rug-check, gem discovery and token info need no key — anyone can verify a token before buying.

Key = authorise, not custody

The API key authorises a swap build/broadcast. It is not a wallet key and cannot sign or move funds.

Per-request authentication

Each request authenticates as the caller; there is no shared operator key that can act on your behalf.

Rotate any time

Create and revoke keys from your account. Compromise of a key does not compromise your wallet.

03 · Fees, transparently

One disclosed fee, no hidden routing

The DEX applies a transparent platform fee that is baked into the quote and the unsigned transaction — you see it before you sign, in the same number you approve. There is no second hidden spread taken after the fact.

04 · Token safety

Rug-gating before you buy

Every token can be rug-checked before purchase: honeypot detection, mint and freeze authority, liquidity lock status, and holder concentration. This is a safety read, not a guarantee.

A safety check flags known risk patterns. It cannot predict a new exploit, a delayed rug, or a team that abandons a token. Treat it as one signal, not as a green light. Always do your own research and verify the contract yourself.
05 · Responsible disclosure

Found a vulnerability?

If you believe you have found a security issue in Autonomous Intelligence — the DEX, the agent rail, the MCP server, or any hosted surface — please report it responsibly. Do not publish the issue publicly until we have had a chance to respond.

Report to

Email hello@autonomousintelligence.io with full reproduction steps. We acknowledge within 2 business days and aim to triage within 5. Please do not test against live user funds.

This page describes our security posture in good faith and is not a warranty, audit, or financial advice. Crypto trading and token launches carry risk; always do your own research. Last reviewed 7 August 2026.