Security
We hold nothing worth stealing. Your keys, your chain, your account.
Security at Greenwood starts from an unusual place: we hold nothing worth stealing. Your keys are on your device and your assets are on a public chain. There is no vault of customer funds at Greenwood to breach.
Your keys#
- Keys are generated and stored in your device's secure hardware. They never touch Greenwood's servers.
- Every transaction requires your passkey: Face ID, Touch ID, or your device's equivalent.
- Sensitive card details are revealed only after passkey authentication and are never stored in the app.
Recovery#
Losing your phone should not mean losing your assets.
- Second device. Add a passkey from another device while you have access, and either one can operate the account. This is the single most useful thing you can do after joining, and we will keep asking until you do it.
- Recovery without Greenwood. Your account is a standard ERC-4337 smart account. We publish a plain-language guide to operating it with any compatible wallet, without Greenwood's app or servers.
If you only ever had one device, recovery depends on your platform's passkey sync. That means Apple or Google, not us. It works well and it is worth knowing that it is the dependency.
What Greenwood cannot do#
- We cannot move your assets.
- We cannot freeze your account or block a withdrawal to your own wallet.
- We cannot recover your account without your participation. That is a feature, and it is why the second-device passkey matters.
What Greenwood can do#
Equally worth stating:
- We can stop serving you through our app, which does not affect your account.
- The card-issuing partner can suspend your card and hold funds relating to a disputed card transaction.
- Where a tokenized asset issuer enforces restrictions at the token level, those restrictions apply regardless of what we would prefer.
How self-custody works#
Your account is self-custodial in the way that matters most: the keys are generated on your device, stored in its secure hardware, and every transaction requires your passkey to authorize. Greenwood never sees your key material and cannot move, freeze, or spend your assets. There is no omnibus account, no pooled customer funds, and nothing at Greenwood worth breaching.
We use passkeys instead of seed phrases because seed phrases are the single biggest cause of lost funds in this industry. Nothing to write down, nothing to screenshot, nothing to lose. Your account is secured by the same biometrics you already trust to unlock your phone, backed by hardware designed to keep secrets.
That convenience does not cost you independence. You can export your keys at any time and operate the account with any compatible wallet, entirely without us. Your account is a standard ERC-4337 smart account on a public chain, so it works the same whether you reach it through our app or someone else's.
Protocol risk and cover#
Earn deposits sit in audited onchain lending protocols. Smart contract risk is real, and we treat it that way: conservative vault selection, overcollateralized markets, and cover for smart contract failure in procurement. Details will be published when finalized, and we will describe them precisely rather than generously.
Responsible disclosure#
Found something? Email security@greenwood.fi. We take reports seriously, respond quickly, and credit researchers who help us keep members safe.