Trust model
This page states what you should trust RTP to do — and what you should not infer from the interface alone.
Keys stay on your device
Section titled “Keys stay on your device”Wallet signing material is intended to live in your browser, not on RTP infrastructure you do not control. Login wallets only prove who you are; they do not replace the Wallet for trades, swaps, or launches. Details: Custody and security and Architecture.
Execution is gated
Section titled “Execution is gated”Even when screens look complete, submitting a launch, trade, swap, tools action, or claim is not open in this build.
Multiple layers enforce that:
- Product lock — RTP keeps signing and submit disabled until the operator opens a unified test window.
- Operator gate — production broadcast stays blocked independently of what you see in the UI.
A preview on screen does not mean you can move funds in production today. What is live is the capability map; Limitations lists what is not built.
Yellow warning dot (incomplete UI)
Section titled “Yellow warning dot (incomplete UI)”Some labels show a yellow warning dot after the text. That means the surface is visible but not finished — honest “Soon” or disabled copy may apply.
Rules of thumb:
- Visible ≠ ready to submit. A yellow dot or an enabled-looking control does not mean signing is open.
- Disabled and yellow can coexist. The dot marks product honesty, not a hidden switch you can bypass.
- Do not treat incomplete Team, Multi, or automation areas as money-ready without an explicit announcement that submit is open.
What RTP does not claim
Section titled “What RTP does not claim”- No third-party security audit is complete — see Security disclosure.
- RTP does not audit every token contract you might trade against.
- Phishing resistance depends on you checking the domain (
rtp.fun,wallet.rtp.fun) and reading what you sign.