> For the complete documentation index, see [llms.txt](https://tryflux.gitbook.io/flux-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://tryflux.gitbook.io/flux-docs/7.-security-and-trust-model.md).

# 7. Security & Trust Model

###

#### 7.1 User Isolation

* All API endpoints are user-scoped via session authentication
* Agents, runs, and metrics are isolated by user ID at the database level
* Cross-user data access is cryptographically impossible

#### 7.2 Wallet Custody & Control

* **Embedded Wallets**: Provisioned by Privy using server-controlled authorization keys
* **Non-Custodial**: Users retain ultimate control through configured signing schemes
* **Policy Integration**: Optional on-chain policies provide additional constraints
* **User Wallets**: Full integration with WalletConnect for self-custodial scenarios

#### 7.3 Execution Guardrails

* **Quote-Only Mode**: Agents can run entirely in simulation without on-chain risk
* **Broadcast Controls**: Runtime flags require explicit opt-in for live execution
* **Transaction Validation**: All quotes are validated against slippage and size limits before signing
* **Audit Transparency**: Complete trail of all decisions and executions

#### 7.4 Data Integrity

* **Server-Authoritative State**: The database is the single source of truth; UI state is derived
* **Transactional Consistency**: MongoDB ensures consistent state across agent operations
* **Receipt Verification**: On-chain receipts are polled and recorded for all broadcasts

***

###


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://tryflux.gitbook.io/flux-docs/7.-security-and-trust-model.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
