Skip to content
frank_

Signing and safety

In short: Frank asks, a human approves new markets, two more layers check, and only then does a separate signer sign. Frank itself never touches a key.

Frank never holds a key. When it wants to act on chain, the request passes through these stages.

Signing path: inside the frank app a request is priced and, for a new market, approved by an operator; it then passes policy limits and the executor; only then does the separate signer service sign it for the chain.frank appRequestFrank asksApprovalhuman OKPolicyhard limitsExecutorone intentsigner serviceSignerallowlist onlysignedChain
  1. Pricing and approval (new markets only). Frank can only propose a token. The pricing service computes the terms, keeps total new FRANK under a ceiling, and refuses terms that wouldn't be backed. An operator approves those exact terms; the approval names a fingerprint of them, so if anything changes in between the approval is refused.
  2. Policy checks the request against limits in code: how much FRANK a market can create, how many markets can be open, whether the price is fresh, and whether the rate is reasonable against the token's price.
  3. Executor simulates the transaction, records a one-time intent, gets it signed, then sends it. Each tool call has one intent id, so retries and crashes never act twice.
  4. Signer holds the only key. It signs only these calls, always with value 0, at most 120 an hour, and with caps on gas and fees:
    • on the treasury: createMarket, updateMarket, closeMarket, vault deposits and withdrawals, and vault admission
    • on an active vault: claimRewards, activateInference

Anything bigger — upgrades, bounds changes, vault caps — goes through the contracts' public timelocks and the admin, not through Frank. Vault admission itself waits 24 hours in public.

How secrets are split

ServiceCan reachSo a break here cannot…
frank (model, DB)internet, signer, sandbox…sign on its own, or read the egress credentials
signer (the key)the chain RPC…do anything but the allowlisted calls
sandbox (Docker socket)the Docker daemon…reach the key or the model
egress (credentials)internet, minus private ranges…be bypassed; it's the machines' only exit and their DNS

Known secret values are also redacted from everything the model sees and every public room event.

The gaps

These, and the contract-level issues, are covered in Security.