Nova is a self-custody wallet built on one premise: trust should be proven, not promised. Secret material is isolated at input, every release is reproducible from public source, and nothing leaves your device that you did not explicitly sign.
Each control below is enforced in code and auditable in the public repository — including the absence of the things we claim not to have.
Recovery phrases and private keys are entered into an isolated input context that shares no state with dapp or rendering layers. Secret material never reaches the DOM, the clipboard, or any network-capable code path.
No analytics SDKs, no crash beacons, no device fingerprinting. The release binary contains zero outbound telemetry endpoints — verifiable in source and observable on the wire.
Every release is built deterministically from public source with signed provenance. Rebuild locally and compare SHA-256 hashes against the release manifest — the binary you run is the code you read.
Before you sign, Nova Shield simulates the outcome locally and screens the request against signed threat lists — unlimited approvals, drainers, honeypots and lookalike addresses are flagged in plain language.
Keys are derived and scoped per chain in separate keystores. A compromised contract or integration on one network has no path to key material belonging to another.
Secrets live only in locked, non-pageable buffers that are overwritten the moment they are no longer needed. Locking the wallet zeroes every byte — nothing survives for swap files, crash dumps or forensic recovery to find.
No. Your phrase is entered through the air-gapped input context and held only in a locked memory region that is zeroed on lock. It is never written to disk, transmitted, or logged — there is no code path that could send it anywhere. You can confirm this in the source.
Nova exposes only your public address and chain ID, then relays signing requests. Every request is decoded by Nova Shield and shown in plain language — what is being approved, for how much, and to whom — before you commit. A dapp receives signatures only when you explicitly approve; it never touches your keys.
Deterministic on-device checks plus cryptographically signed threat lists: approvals with unlimited spend, setApprovalForAll to unverified contracts, known drainer addresses, honeypot bytecode patterns, and lookalike-address poisoning. Evaluation runs locally — the lists are data, not a remote kill switch.
Yes. Clone the repository, run the deterministic build, and compare the SHA-256 hash of your output against the signed release manifest. Build provenance is published with every release, so the artifact in the store can be traced back to an exact commit.
Only what the networks require: signed transactions and the RPC reads needed to fetch balances and state, sent to endpoints you can inspect and change. No analytics events, device identifiers, or usage metrics — if you block our domains entirely, the wallet still works.
Nova speaks to 120+ networks. This is what on-chain activity looks like right now — blocks ticking, gas moving, transactions settling.
Read the code, reproduce the build, watch the wire. Nova is designed to survive that scrutiny.