Security
The design goal is simple: a bug in Superperps should not be able to move your money. Here is how the pieces enforce that.
Non-custodial by construction
Funds are in Lighter's contract on Robinhood Chain. Superperps has no deposit address, no treasury and no way to move your collateral.
Keys never leave your browser
The Lighter API key is generated by Lighter's own signer compiled to WebAssembly, running in your tab. It is stored in localStorage for this origin and can be forgotten from Setup at any time.
Scoped permissions
A Lighter API key can trade, cancel and change leverage on the account it belongs to. Transfers to other accounts and fast withdrawals require an L1 wallet signature the key does not have.
A human confirms every order
The model cannot call the exchange. Order tools are client-side: the browser renders a card from live data, and only your click signs and sends.
Sign-In With Ethereum
Login is a signed message with a single-use nonce and a domain binding, verified server-side. Sessions are HttpOnly cookies signed with HS256.
Thread isolation
Each chat is a Cloudflare Durable Object named after your address. The Worker rejects connections to any thread you do not own.
Minimal data
We store your address, account index, threads and an order journal in Cloudflare D1. No email, no KYC, no analytics SDKs on the app.
What you should still do
- Only register a trading key on a device you control. Forget it from Setup before lending the device.
- Read the confirmation card. The assistant can misread you; the card is the truth.
- Keep leverage you can survive. Liquidation prices are shown on every position for a reason.
- Found a vulnerability? Email security@superperps.io before disclosing it publicly.