Non-custodial systems guarantee that only you control your money. Learn why this design is critical for security and trust.
The so-what: In a custodial system (like a bank or centralized exchange), they hold your funds and can block or lose them. In a non-custodial system like FiLot, you retain full ownership of your keys and assets. Nobody can move a single cent without your wallet's signature.
Imagine a bank vault. A custodial system is like depositing your money with a banker who holds the keys and decides whether to let you in.
A non-custodial system is like having a secure safe inside your own home. You own the private keys and the safe combination. FiLot is a helper that formats papers for you, but only you can turn the key to open the safe.
Your wallet holds a private key. When an app wants to move your funds, it cannot do it. All it can do is build a transaction and hand it to your wallet with a request.
Your wallet shows you what the transaction does and waits. If you approve, it uses your key to produce a signature, a mathematical proof that the holder of that key authorised this exact instruction. The network checks the signature against your public address and rejects anything that does not match.
The key itself never leaves your wallet. It is not sent to the app, not sent to the network, and not sent to us. This is why a non-custodial app can be useful without being trusted: the worst it can do is ask.
Custody is not purely a bad thing. A bank can reverse a fraudulent transfer, reset your password, and refund you when it goes wrong, precisely because it is in control.
Non-custodial means nobody can do any of that for you. There is no password reset, no support line that can move funds back, and no reversing a confirmed transaction. Self-custody hands you the upside and the responsibility in the same motion, and it is worth choosing deliberately rather than by accident.
In practice this comes down to your recovery phrase. It is the wallet. Anyone who reads it owns everything in it, forever, and nobody who loses it gets back in. Keep it offline, keep it somewhere a fire or a flood will not take it, and treat any request to type it anywhere as theft in progress. No legitimate app, FiLot included, ever needs it.
This is the part that gets skipped. Self-custody removes one category of risk and leaves others completely intact.
The signing screen is the last honest moment in the process, so it is worth ten seconds.
A wallet that warns you, or refuses to simulate, is doing its job. Pushing past that warning is the single most expensive habit in crypto.
Connecting a wallet to a site is not the same as authorising payment. A connection normally grants read access: your public address and balances, which are public on-chain anyway. Moving anything still requires a separate signature you have to approve.
So connecting to view a dashboard is low risk. It is the prompts after connecting that deserve your attention.
FiLot is an analysis and bookkeeping tool, not financial advice, and this page is general education rather than a security audit of your setup.
Next: how to buy gold on Solana, and what tokenised gold asks you to trust that a bar in your hand does not.
FiLot tracks your physical gold and models Solana DeFi in plain language, so you stay in control.
Try the Beta