Safety model
How Vision keeps you in control of every signature and every transfer.
Safety in Vision means one thing: nothing moves until you confirm. This page explains exactly what Vision can and cannot do with your wallet and your data, including where your keys actually live, which depends on which wallet you use. Two ways to hold. Where the keys live differs. The confirm step never does. Where your keys live Vision has two wallet modes, and they are genuinely different. Be clear which one you're using.
The Vision Wallet. Created for you when you sign up, and the wallet every signed-in account uses. It is custodial: Vision holds the authority to sign for it, which is what makes gasless one-tap trading across chains possible. Treat it like a hosted account rather than a hardware wallet. Your own wallet. Not supported. Until 21 August 2026 you could connect one as a guest on the public Terminal, where Vision was fully non-custodial and never saw those keys.
That surface has been retired, so the Vision Wallet is now the only wallet Vision uses. What "custodial" does and doesn't mean here Custodial is the honest word, and we use it. But it is worth being precise about what is actually held, because the usual mental picture (a private key sitting in a company database) is not what happens. No one holds a complete, reconstructable key. The key is split into shares held by separate parties.
They are brought together only inside a secure enclave, only for the instant a transaction is signed, and the result is never written down anywhere. Vision's own records contain no key material. What we store against your account is your two public addresses and an identifier for the signing service. There is nothing in our database that could move your funds on its own. What we do hold is the authority to sign.
The ability to ask that service for a signature on your behalf, once you have confirmed. That is the part that makes it custodial, and it is the part that matters when you decide how much to keep here. Decide with the right facts. Do not read "no reconstructable key" as "not custodial". It is custodial, and you are trusting Vision with the authority to sign. There is no self-custody option in Vision: the public Terminal, where you traded from your own wallet, was retired on 21 August 2026.
Decide how much to keep here on that basis. You can export your keys at any time from Settings and take them elsewhere. What Vision can do Read your wallet's public balances and on-chain history. Build a transaction and show you exactly what it will do, before anything is signed. Sign and submit that transaction with the Vision Wallet. Only after you confirm it. Index public on-chain data and aggregate it back into your chat.
What Vision cannot do Move funds without you confirming first. There is no path that skips the card. Touch the keys of a wallet you connected yourself. Trade in the background, on a schedule, or on its own initiative. Recover a wallet you connected yourself. Those keys were never ours. Every action has a preview Every state-changing action (a swap, a send, a transfer between chains) returns a structured preview card first.
The card shows what you pay, what you receive, the fees and the route. Nothing is signed until you press the button on that card. If anything looks wrong, dismiss it and ask again. Confirm carefully. The preview card is your last checkpoint. If you don't recognise the destination address or the amount, dismiss the card and ask Vision to explain it before you confirm. Risk reports for unknown tokens When you mention a token that's new or low-liquidity, Vision can run a risk report covering mint authority, freeze authority, LP locks, top-holder concentration, and contract age.
Use it before swapping into anything obscure. Phishing and address verification For sends, Vision resolves named contacts you've saved against the actual address it'll send to. The preview card always shows the full destination so you can verify it before approving. How Vision is reviewed Vision is custodial, so the honest version of this matters more than a reassuring one. Our security work is our own: we review the application ourselves and fix what we find.
There is no third-party audit behind Vision, and there is no contract audit, Vision has no contracts of its own, it routes through the chains and venues you already trade on. If you see the word "audited" attached to Vision anywhere, it did not come from us. The most recent review was in July 2026. It covered who can reach our internal operations, what the chat can be talked into by text it did not write, how uploaded files are stored and served, and whether the app can be embedded in someone else's page.
Everything found was fixed and re-tested; the specifics are in the changelog. What that review did not cover. Our marketing and documentation sites were not part of it, and neither was a line-by-line review of the code that runs in your browser. Both are worth doing and neither has been done yet. We would rather say so than let a summary imply more than we checked. If you find something, email hello@askvision.ai.
Please tell us before you tell anyone else, and never test a finding against another person's account or funds.