Skip to main content
Security at Grand is not a feature layered on top of the product — it is the foundation the entire app is built on. Every interaction, from logging in to executing a trade, is protected by a combination of device-bound passkeys, biometric authentication, and independently audited smart contracts. You remain in control of your assets at all times.

Core security principles

Self-custody by default

You own your wallet and your keys. Grand never takes control of your assets, which eliminates counterparty risk entirely.

Passkey and biometric login

Every trade, transfer, or settings change requires biometric approval via Face ID or Touch ID. Your passkey is bound to your device and cannot be extracted.

Audited-only listings

Independent security audits validate the integrity of Grand’s partners contracts and infrastructure before they go live.

No hidden risks

All assets are held on-chain, visible and verifiable by anyone. Nothing is held with intermediaries.

Additional protections

Gas-free transactions

Grand covers gas costs on your behalf. You never need to manually configure gas settings, which eliminates a common source of errors and exploits.

Withdrawal controls

Every withdrawal is gated behind your passkey. No action can be taken without biometric confirmation from your registered device.

Social recovery

If you lose your device, you will be able to recover access through your Apple or Google login combined with Grand’s passkey recovery options — without exposing your private keys.
Social recovery is coming soon. In the meantime, keep your Apple or Google account secure, as it is your primary recovery path.

Audited-only listings

Grand only surfaces assets, protocols, and applications that have passed a security review. Nothing is listed without verification.
CategoryWhat it means
Audited tokensAssets backed by reputable audits and proven security standards.
Verified protocolsDeFi protocols and vaults with third-party security reviews.
Trusted dAppsApplications must pass both security and reliability checks before integration.

Security FAQ

You can recover your account using your Apple or Google login combined with Grand’s passkey recovery options. Your private keys are never exposed during this process.
Make sure your Apple ID or Google account has two-factor authentication enabled. This is your primary recovery path if you lose access to your device.
No. Grand is fully self-custodial. Your assets are always yours, held on-chain. Grand never takes custody of your funds or controls your private keys.
All Grand smart contracts are independently audited before deployment and continuously monitored after launch. Audit reports will be published in Grand’s transparency documentation.
A passkey is a cryptographic credential bound to your specific device and biometrics. It replaces passwords with something that cannot be phished, guessed, or stolen — because it never leaves your device. Grand uses passkeys so that every sensitive action requires physical confirmation from you.