Trust and Safety Architecture
Autonomy without safety is not a product. It is a liability.
Catto's trust model is built on four non-negotiable principles:
1. Always Non-Custodial
Catto never holds private keys. All execution flows through wallet-native signing. User funds remain under the user's cryptographic control at all times.
2. Explicit Permission Scoping
Every autonomous capability requires explicit user authorization. Catto cannot self-expand its execution boundaries. You define the scope; Catto operates within it.
3. Full Execution Transparency
Every agent action is logged, timestamped, and visible in the user's activity history. Nothing happens silently.
4. Staged Autonomy
The default state is always the most conservative configuration. Users must actively expand Catto's autonomy level. The system is never aggressive by default.
Last updated