How Ava is structured so your funds stay in your wallet — and what the safety boundary actually is.
Safety first. You're in complete control. Always.
The three pillars:
The rest of this page is the detail behind those three sentences.
In your wallet. Not on Ava's servers, not in an "Ava balance" held by us, not in a multi-sig vault we control. There is no Ava database row that says "user X has Y USDC."
If you choose a separate Ava smart wallet for Auto mode, that wallet is yours too — your main wallet owns it, and you can withdraw from it anytime.
Ava is three things:
Manual mode: your signature. Ava prepares, you sign, your wallet sends it. Nothing moves without you.
Auto mode: the agent permission. To use Auto on your own wallet, you upgrade it once (EIP-7702 — same address, same keys) so it can hold agent permissions; or you use a separate Ava smart wallet. Either way, every Auto action runs under a permission you signed:
Your wallet enforces the permission on-chain: anything outside it is refused by the chain. Ava can't create or widen a permission — only your signature can — and a permission never gives Ava full control of your wallet. See Permissions & Limits.
| Ava can… | Ava cannot… |
|---|---|
| Read public on-chain data about your wallet | Read your seed phrase or private key (it doesn't have them) |
| Read your portfolio via data providers (e.g. Zerion) | Use an app your permission doesn't allow |
| Prepare a transaction for you to sign | Spend more than your permission's limit, or act after it expires |
| In Auto mode, act inside a permission you signed | Create or widen its own permission — only your signature can |
| Watch and alert 24/7 | Stop you from pausing a job, revoking a permission, or undoing the upgrade |
Every action Ava takes lands on-chain. You can verify each one:
from (your wallet), to (the protocol contract — e.g. the Aave pool), and the amounts.If a transaction ever lands that you didn't expect, stop first, ask later: undo your wallet's upgrade or disable your permissions. See Revoking Access.
Ava can be wrong — bad recommendation, bad timing, missed risk. The non-custodial design means "wrong" is bounded:
That's the point of the design: bound what Ava can do explicitly, on-chain, so you can sleep. It bounds Ava — not the market. Spending limits cap what Ava is authorized to spend. They don't cap losses on your DeFi positions.