Security & platform docs

Know what protects the workspace.

This page explains Serum's Turnkey-secured managed wallet model, mandatory 2FA, protected sessions, optional passkeys, operator controls, and the beta posture around live funds.

Security posture
Custody gates2FA enforcedBefore wallet access
Wallet custodySerum managedSigning keys protected by Turnkey
Workspace modelTenant isolatedAccount bound controls
Operator trailAuditableWithout private material
Controlled private beta

Serum uses Turnkey-secured managed wallets, mandatory 2FA, protected sessions, and optional passkeys. No custody or trading system is risk free, so keep beta balances limited to what you can afford to put at risk.

01

Serum documentation

Security architecture

Serum treats the application, Turnkey wallet boundary, database, and deployment environment as one operating security surface.

  • Each account operates inside a tenant scoped workspace with isolated wallet sets, settings, bots, and activity.
  • Authenticated browser sessions are server side, expire automatically, and can be revoked by an owner.
  • Sensitive responses are marked private, and private material is excluded from application and audit logs.
  • Policy checks are enforced again on the server before Turnkey signing or custody actions are allowed.
02

Serum documentation

Account & access protection

Access controls are designed so a password alone is not enough to operate custody.

  • Invited users must replace their temporary password before using authenticated APIs.
  • Sensitive actions can be approved with registered passkeys instead of repeatedly exposing passwords and one time codes.
  • Owners can disable accounts, revoke active sessions, and require passkey based access.
  • Sensitive authentication and recovery actions are rate limited and recorded without storing credentials.
03

Serum documentation

Turnkey-secured managed wallets

Serum uses Turnkey-backed wallet infrastructure to protect signing keys while Serum operates each account's managed treasury and execution wallets.

  • Each Serum account receives a separately tracked treasury and execution-wallet set inside Serum's Turnkey organization.
  • Serum retains managed signing authority so confirmed trades, Quick Bundle, and armed automation can execute without wallet popups.
  • Current Turnkey wallet private keys cannot be revealed or exported through Serum; supported assets leave through protected external withdrawals.
  • 2FA is required before wallet creation and sensitive custody actions; passkeys add phishing-resistant account access when enabled.
  • Legacy encrypted-key tooling is restricted to pre-Turnkey internal wallets and is not part of new-user onboarding.
04

Serum documentation

Transaction safeguards

High impact actions add deliberate friction, explicit confirmation, and server side verification.

  • External withdrawals are treasury only and require passkey or fallback password plus 2FA approval, an exact confirmation phrase, and simulation.
  • Withdrawal policy verifies the selected treasury balance, destination, token program, protected signature, and simulation before signing.
  • Cross account treasury transfers require separate authorization by the source and destination accounts.
  • Preflight checks, transaction state, and an auditable activity trail remain visible to the operator.
05

Serum documentation

Operational controls

Automation is subordinate to the operator. Serum is built around clear limits and an accessible stop control.

  • Operators can pause automation without dismantling the workspace.
  • Wallet reserves, trade sizing, price impact, hourly activity, and loss limits are configurable.
  • Bot and wallet relationships are verified before transaction signing.
  • Every workspace retains manual execution and records material actions for later review.
06

Current status

Private beta posture

Serum is suitable for controlled beta testing with limited balances. Turnkey, mandatory 2FA, and protected sessions materially strengthen the custody boundary, but the product remains beta software.

Implemented now

Isolated workspaces, Turnkey-secured managed wallets, mandatory 2FA, guarded withdrawals, configurable controls, encrypted offsite backups, and auditable operator actions.

Before broader custody

Continued restore drills, production monitoring, independent security review, and measured capacity validation as the beta grows.

Serum provides execution infrastructure, not financial advice, a guarantee of performance, or a guarantee against loss.

Private beta

Ready to enter the lab?

Tell us whether you launch, operate, or trade new markets. Access requests are reviewed manually.

Request access