Skip to content
HomeEnter terminal

Trust model

This page states what you should trust RTP to do — and what you should not infer from the interface alone.

Wallet signing material is intended to live in your browser, not on RTP infrastructure you do not control. Login wallets only prove who you are; they do not replace the Wallet for trades, swaps, or launches. Details: Custody and security and Architecture.

Even when screens look complete, submitting a launch, trade, swap, tools action, or claim is not open in this build.

Multiple layers enforce that:

  • Product lock — RTP keeps signing and submit disabled until the operator opens a unified test window.
  • Operator gate — production broadcast stays blocked independently of what you see in the UI.

A preview on screen does not mean you can move funds in production today. What is live is the capability map; Limitations lists what is not built.

Some labels show a yellow warning dot after the text. That means the surface is visible but not finished — honest “Soon” or disabled copy may apply.

Rules of thumb:

  • Visible ≠ ready to submit. A yellow dot or an enabled-looking control does not mean signing is open.
  • Disabled and yellow can coexist. The dot marks product honesty, not a hidden switch you can bypass.
  • Do not treat incomplete Team, Multi, or automation areas as money-ready without an explicit announcement that submit is open.
  • No third-party security audit is complete — see Security disclosure.
  • RTP does not audit every token contract you might trade against.
  • Phishing resistance depends on you checking the domain (rtp.fun, wallet.rtp.fun) and reading what you sign.