Shared responsibility: what KAKR secures vs. what you secure

PTERI removes whole classes of risk by design — but a few things stay on you.

Updated September 14, 2026 · 1 min read

PTERI's zero-custody, signature-based model (see PTERI's threat model) removes entire categories of risk from KAKR's side of the line — there's no password database to breach and no shared secret to phish. But security is still a shared job:

What KAKR's platform is responsible for

  • Verifying signatures correctly and never storing or reusing a private key
  • Issuing single-use, short-lived challenges that resist replay
  • Publishing service status and responding to reported vulnerabilities (see reporting a security vulnerability)

What you're responsible for

  • Keeping your device and its OS secure — PTERI doesn't protect against a compromised device or user-approved malware
  • Backing up your recovery phrase or enabling encrypted cloud backup before you need it (see recovering account access)
  • Protecting your API credentials the same way you'd protect any production secret (see creating your first API key)
  • Reviewing what you're signing — a real signature request is still only as safe as your attention to what it says it's approving

Still stuck?

Ask Kai about this article, or open a ticket with our team.

Submit a ticket