SECURITY MODEL

Security begins with
honest boundaries.

Vorka reduces single-device failure and separates recovery from everyday activity. It does not make a compromised computer safe, reverse confirmed transactions or remove the need to verify what you sign.

01SECURITY MODEL

No single everyday device controls recovery.

Primary is authorized for normal Vault operations. Recovery is a separate authority designed to replace Primary. Keeping them on different physical devices limits the damage caused by losing one device or exposing one operational role.

The Vault contract enforces these roles onchain. The desktop application coordinates requests, but it does not become the owner of the Vault.

PPRIMARYNormal authority
ONCHAIN RULESVORKA VAULTHolds supported assets
RRECOVERYReplacement authority

02TRUST BOUNDARIES

Know where trust still exists.

Self-custody does not eliminate trust; it changes where trust is placed. Vorka’s security depends on the deployed Vault code, the application build you run, the device holding encrypted material, your password and the computer used during signing.

Vault contract
Enforces Primary and Recovery permissions
Vorka application
Builds and displays requested operations
USB device
Stores encrypted private material
Your computer
Displays input and submits signed data
You
Protect passwords and verify intent

03PROTECTION GOALS

What the architecture is designed to protect.

  1. Loss of Primary.Recovery can authorize a replacement without changing the Vault address.
  2. Routine Recovery exposure.Recovery is not required for daily signing and can remain offline elsewhere.
  3. Plaintext device theft.Private material is stored encrypted rather than as a directly readable key file.
  4. Custodial reset risk.Vorka cannot reset your password or silently take over your Vault.
  5. Address disruption.Replacing Primary changes authorization, not the address holding the assets.

04LIMITS

What Vorka cannot guarantee.

No software wallet can promise that private material is impossible to extract while it is actively being used on a fully compromised host. Encryption protects material at rest; authentication necessarily makes signing capability available during an authorized session.

  1. Compromised computer.Malware may manipulate the interface, capture passwords or target an unlocked session.
  2. Incorrect approval.A valid signature cannot distinguish a deliberate transaction from one the user misunderstood.
  3. Confirmed transactions.Recovery cannot reverse blockchain finality or recover assets sent to the wrong address.
  4. Both devices lost.Vorka has no custodial backdoor capable of recreating missing private keys.
  5. Protocol risk.Using DeFi introduces smart-contract, oracle, liquidity and network risks outside the Vault itself.

05SAFE OPERATION

The architecture only works if separation is maintained.

  1. Store Recovery elsewhere.Do not leave it connected, carry it beside Primary or keep both in the same bag.
  2. Use a strong unique password.Length and uniqueness matter more than decorative complexity rules.
  3. Verify every operation.Check the network, destination, amount and permission before signing.
  4. Keep the host maintained.Apply operating-system and Vorka updates from trusted sources.
  5. Respond to suspicion early.If Primary may be compromised, stop using it and replace its authority with Recovery.

06RESPONSIBLE DISCLOSURE

Found something that could put users at risk?

Do not publish exploitable details or access another user’s data. Send a concise report with affected version, reproduction steps, impact and any proposed mitigation.

SEPARATE THE ROLES

Keep everyday access close and recovery somewhere safer.

Every Vorka pack includes both encrypted devices and one dedicated Vault.

View pack — €99