Satra is non-custodial by architecture, not by promise. Keys are generated on your device, stored on your device, and never sent anywhere — and because every line of code is public, you don’t have to take our word for it.
When you create a wallet, Satra derives your recovery phrase and private keys locally and writes them to an encrypted database that never leaves the phone. Import works the same way — recovery phrase, single private key, or a watch-only address that carries no keys at all.
An optional passphrase adds a word only you know — a different wallet exists behind every one you type. Nothing about it is stored, anywhere.
Generated on device. Never uploaded, never emailed, never in a screenshot. Write it down and keep it private.
One local database, on one phone, behind your passcode.
No accounts. No cloud backup. No custody. Satra syncs balances directly from public networks — there is no server of ours to breach, subpoena, or lose.
Self-custody protects you from everyone else’s servers. On-device protection guards the device in your hand: a passcode gates the app, biometrics open it fast, auto-lock closes it the moment you look away, and erase protection wipes wallet data after repeated failed attempts.
Every one of these controls runs locally. Turning them on requires no account — because there isn’t one.
Every line of Satra is public under the Apache 2.0 license — key derivation, local storage, sync, all of it. Security claims you can read are worth more than security claims you’re asked to believe.
Balances come straight from public Electrum servers and RPC providers. When a provider is slow, partial, or down, Satra shows the sync state as it is — it never dresses up incomplete data as complete.
Import an address without its keys to monitor balances and activity. A watch-only wallet carries zero spending power — the safest way to keep an eye on cold storage.