Shared responsibility: what KAKR secures vs. what you secure
PTERI removes whole classes of risk by design — but a few things stay on you.
PTERI's zero-custody, signature-based model (see PTERI's threat model) removes entire categories of risk from KAKR's side of the line — there's no password database to breach and no shared secret to phish. But security is still a shared job:
What KAKR's platform is responsible for
- Verifying signatures correctly and never storing or reusing a private key
- Issuing single-use, short-lived challenges that resist replay
- Publishing service status and responding to reported vulnerabilities (see reporting a security vulnerability)
What you're responsible for
- Keeping your device and its OS secure — PTERI doesn't protect against a compromised device or user-approved malware
- Backing up your recovery phrase or enabling encrypted cloud backup before you need it (see recovering account access)
- Protecting your API credentials the same way you'd protect any production secret (see creating your first API key)
- Reviewing what you're signing — a real signature request is still only as safe as your attention to what it says it's approving