KYKY Labs / User-held keys

The self-custodyfinance company.

KYKY Labs builds financial software around user-held keys. KYKY Wallet brings that model to iPhone and browser clients; KYKY Names adds a public, controller-signed record.

@

Every name points to a controller-signed record. Public profiles are server-checked and readable without an app.

Three to twenty characters. Start with a letter; use lowercase letters, numbers, and single underscores.

Explore KYKY Wallet

USER-HELD KEYSIPHONE CLIENTBROWSER EXTENSION CONTROLLER-SIGNED NAMESNO ANALYTICS OR TRACKING SDKS
01

The product constellation

One company / three product surfaces

Control should travel
with the person.

KYKY begins with one wallet implemented for two local client environments, plus a signed-name system that remains readable on the public web. KYKY Assurance documents the checks and limitations underneath all three.

See how the system fits together

02

Product one / KYKY Wallet

One wallet / two local clients

From pocket
to browser.

KYKY Wallet is implemented for iPhone and Chromium browsers. The client surfaces differ, but both are built around a local wallet boundary and an explicit review before signing. Distribution links appear only when an official listing is configured.

Enter the wallet product

Illustrative information architecture. No account, balance, quote, projection, or performance data is shown.

Illustrative client structure based on the existing Chromium extension. Distribution links are shown only when officially configured.

01 / SEE

Eleven networks,
one iPhone view.

Including native Bitcoin and Solana.

02 / CONNECT

Per-origin browser
permissions.

A site receives an account only after approval.

03 / COMPARE

Available route
details in view.

Minimum received and estimated fees before approval.

04 / APPROVE

The signer gets
the final word.

Device authentication or hardware confirmation, by path.

Digital assets can lose value, transactions may be irreversible, and losing recovery credentials can mean losing access. KYKY Labs does not provide investment advice.

03

KYKY Names / the signed object

Readable name / named controller

A handle with
a cryptographic edge.

A KYKY profile checks the displayed record against the controller named inside it before supported fields render. That is a key-to-record check, not proof of a person, organization, handle history, or payment purpose.

Read the signed-name model

The canonical record format with neutral demonstration data. No user address is shown.

04

Public profiles / proof with limits

PUBLIC / CHECK 001

Illustrative profile data, not a live @maya record. The production renderer checks the record against its named controller and ships zero client JavaScript.

Readable in any browser

The check is visible.
So is its boundary.

The public renderer checks the record signature against the controller named in that same record. The delivered profile page runs no client JavaScript, and V1 address types whose exact case cannot be authenticated are withheld from the web.

Follow the verification path

THE CHECK ESTABLISHES Record ↔ named controller

The renderer checks that the displayed canonical record was signed by the controller named inside that record.

THE CHECK DOES NOT ESTABLISH Person, history, or purpose

It does not independently prove a real person, organization, handle history, payment purpose, or that a recipient is safe.

05

KYKY Assurance / trust architecture

Check / limit / decide

Security without
the mythology.

KYKY documents the checks performed by each surface, the data those checks cover, and the conclusions they cannot establish. Controls reduce risk; they do not eliminate it.

Your device controller signs the canonical record KYKY registry serves the record and the controller named inside that record KYKY client checks signature/controller match Profile page checks before rendering signed record record served signature matches the named controller canonical value changed signature fails · nothing shown BOUNDARY / this check does not independently prove identity or handle-to-controller history Your deviceController signs canonical record signed record KYKY registryServes record and controllernamed inside that record record served Checking surfaces KYKY clientmatch checked Profile pagematch checked controller match checked CONTROLLER MATCHSupported fields may render canonical value changed SIGNATURE FAILEDNo address shown
Tests

Automated tests cover wallet cryptography, signing, transaction, and record paths.

Conformance

Signing is held to golden vectors: known inputs, byte-exact expected outputs.

Internal adversarial review

Value-movement paths receive dedicated internal adversarial review.

Privacy as practice

No analytics or tracking SDKs are included in KYKY Wallet.

Open the KYKY trust center

KYKY Labs

Keep the keys.
Understand the system.

Check a name or explore the wallet built for iPhone and browser clients.

@

Every name points to a controller-signed record. Public profiles are server-checked and readable without an app.

Three to twenty characters. Start with a letter; use lowercase letters, numbers, and single underscores.