Non-Custodial Design

How Ava is structured so your funds stay in your wallet — and what the safety boundary actually is.

Non-Custodial Design#

Safety first. You're in complete control. Always.

The three pillars:

  • Transparency — every action is visible. You see each step in the chat, every job run is listed in Ava Studio, and every on-chain action is verifiable on a block explorer.
  • Security — non-custodial by design. Funds stay in your wallet and you hold your keys. If you let Ava act on its own, it can only operate inside an agent permission you sign — limits it cannot exceed.
  • Control — you decide how Ava acts. Sign each action yourself, or let Ava act on its own inside limits you set. Pause a job, change its limits, or revoke permission anytime.

The rest of this page is the detail behind those three sentences.

Where your funds actually are#

In your wallet. Not on Ava's servers, not in an "Ava balance" held by us, not in a multi-sig vault we control. There is no Ava database row that says "user X has Y USDC."

If you choose a separate Ava smart wallet for Auto mode, that wallet is yours too — your main wallet owns it, and you can withdraw from it anytime.

What Ava is — concretely#

Ava is three things:

  1. A language interface in Telegram that helps you understand your positions and decide what to do.
  2. A transaction preparer: in Manual mode, Ava builds the transaction and you sign it in your own wallet.
  3. An optional operator under a permission you sign: in Auto mode, Ava can act on its own — one-off actions you confirm, and standing jobs you set up, like health-factor protection — only inside that permission.

The safety boundary#

Manual mode: your signature. Ava prepares, you sign, your wallet sends it. Nothing moves without you.

Auto mode: the agent permission. To use Auto on your own wallet, you upgrade it once (EIP-7702 — same address, same keys) so it can hold agent permissions; or you use a separate Ava smart wallet. Either way, every Auto action runs under a permission you signed:

  • The apps it may use, by contract address.
  • A total spending limit per token — a running total that doesn't refill.
  • An expiry — every permission has one.

Your wallet enforces the permission on-chain: anything outside it is refused by the chain. Ava can't create or widen a permission — only your signature can — and a permission never gives Ava full control of your wallet. See Permissions & Limits.

What Ava can and cannot do#

Ava can…Ava cannot…
Read public on-chain data about your walletRead your seed phrase or private key (it doesn't have them)
Read your portfolio via data providers (e.g. Zerion)Use an app your permission doesn't allow
Prepare a transaction for you to signSpend more than your permission's limit, or act after it expires
In Auto mode, act inside a permission you signedCreate or widen its own permission — only your signature can
Watch and alert 24/7Stop you from pausing a job, revoking a permission, or undoing the upgrade

The "trust nothing, verify everything" path#

Every action Ava takes lands on-chain. You can verify each one:

  1. Ask Ava for the transaction hash, or open the wallet's recent activity. Standing-job runs are also listed in Ava Studio.
  2. Inspect the transaction on a block explorer (Etherscan, Basescan).
  3. Check from (your wallet), to (the protocol contract — e.g. the Aave pool), and the amounts.

If a transaction ever lands that you didn't expect, stop first, ask later: undo your wallet's upgrade or disable your permissions. See Revoking Access.

What if Ava is wrong?#

Ava can be wrong — bad recommendation, bad timing, missed risk. The non-custodial design means "wrong" is bounded:

  • Wrong recommendation in Manual mode → you decline. No funds move.
  • Wrong action in Auto mode → it happens inside the permission: only its apps, within its spending limit, before its expiry.
  • Bad luck (oracle anomaly, market gap, congestion) → the same bound applies. There's no path where Ava acts outside the permission you signed.

That's the point of the design: bound what Ava can do explicitly, on-chain, so you can sleep. It bounds Ava — not the market. Spending limits cap what Ava is authorized to spend. They don't cap losses on your DeFi positions.