Signing and safety
In short: Frank asks, a human approves new markets, two more layers check, and only then does a separate signer sign. Frank itself never touches a key.
Frank never holds a key. When it wants to act on chain, the request passes through these stages.
- Pricing and approval (new markets only). Frank can only propose a token. The pricing service computes the terms, keeps total new FRANK under a ceiling, and refuses terms that wouldn't be backed. An operator approves those exact terms; the approval names a fingerprint of them, so if anything changes in between the approval is refused.
- Policy checks the request against limits in code: how much FRANK a market can create, how many markets can be open, whether the price is fresh, and whether the rate is reasonable against the token's price.
- Executor simulates the transaction, records a one-time intent, gets it signed, then sends it. Each tool call has one intent id, so retries and crashes never act twice.
- Signer holds the only key. It signs only these calls, always with value 0, at most 120 an hour, and with caps on gas and fees:
- on the treasury:
createMarket,updateMarket,closeMarket, vault deposits and withdrawals, and vault admission - on an active vault:
claimRewards,activateInference
- on the treasury:
Anything bigger — upgrades, bounds changes, vault caps — goes through the contracts' public timelocks and the admin, not through Frank. Vault admission itself waits 24 hours in public.
How secrets are split
| Service | Can reach | So a break here cannot… |
|---|---|---|
frank (model, DB) | internet, signer, sandbox | …sign on its own, or read the egress credentials |
signer (the key) | the chain RPC | …do anything but the allowlisted calls |
sandbox (Docker socket) | the Docker daemon | …reach the key or the model |
egress (credentials) | internet, minus private ranges | …be bypassed; it's the machines' only exit and their DNS |
Known secret values are also redacted from everything the model sees and every public room event.
The gaps
These, and the contract-level issues, are covered in Security.