PTERI's threat model — what's protected and what isn't

Threats eliminated by design vs. explicitly out of scope.

Updated July 8, 2026 · 1 min read

PTERI treats security as a property of architecture, not a layer bolted on afterwards.

Threats eliminated by design

  • Credential theft and replay attacks — there are no shared secrets to steal
  • Phishing of passwords or OTP codes — there are none
  • Impersonation by infrastructure — the platform can verify but never sign on your behalf
  • AI forgery — proofs require a private key that never leaves your control

Explicitly out of scope

PTERI does not protect against:

  • Compromised devices
  • User-approved malware
  • Physical coercion

Keep your device secure and review every approval request before you sign it.

Still stuck?

Ask Kai about this article, or open a ticket with our team.

Submit a ticket