01 Secrets stay native.
The webview never receives a generated mnemonic, seed, private descriptor, extended private key, or decrypted signing material. Rust creates software-wallet entropy with the operating system CSPRNG and presents recovery words through a native sheet.
02 Your encrypted wallet stays portable.
Groot protects a software wallet with authenticated encryption and your wallet passphrase. The encrypted profile can move with you, so a unique, long passphrase remains essential.
03 The PSBT is the record.
Review data comes from the persisted unsigned transaction. Rust checks inputs, fees, recipient, change, wallet ownership, and proposal identity again before signing, merging, finalizing, or broadcasting.
04 Hardware identity is checked.
USB operations reopen the exact signer by its validated fingerprint. Imported signatures must add valid policy signatures to the same transaction; changed or unrelated PSBTs fail closed.
05 Your node defines the network edge.
Wallet balances, history, fees, and broadcast use the Bitcoin Core node selected for that wallet. Connect locally or to your own remote node over HTTPS. There is no silent public wallet backend.