ANA.FI
/
TRUST & SECURITY
Nobody can move
your money but you.
Five parties touch a payment. Your wallet holds the funds, and the engine can only act inside the limits you signed. Everyone else is either blind or powerless — by construction, not by promise.
POLICY SIGNED
POLICY EXECUTED
TRANSACTIONS · TX
FUNDS · $
YOU
funds + wallet key
ATTESTED ENGINE
Anafi · signs inside your limits
CHAIN
executes the signed tx
OFF-RAMP PROVIDER
converts and pays out
PAYEE
gets a bank transfer
tx
tx
tx
$
$
FUNDS
Never leave your wallet before execution.
LIMITS
Enforced on-chain automatically.
RULES
Encrypted on your device. Visible only to the signer.
REVOCATION
One call from your wallet. Instant.
01
WHO HOLDS WHAT
No wallet- or token-wide approvals.
Encrypted and verifiable rules.
What each party holds the moment you sign a policy, and what changes when it runs.
HAS ACCESS
NO ACCESS
YOU
ATTESTED ENGINE
ANAFI
OFF-RAMP PROVIDER
FUNDS
KEYS TO YOUR WALLET
A KEY FOR A CERTAIN ACTION
KYC DATA
POLICY DETAILS
PAYOUT DETAILS
POLICY TRIGGERS
YOU
everything that matters. Sign once, then go offline.
ATTESTED ENGINE
sees the rule only inside the enclave.
ANAFI
no funds, no rule, no identity. Can delay a payment; never read, redirect or create one.
OFF-RAMP PROVIDER
the regulated side: your identity and where the money lands.
02
FAILURE MODES
If something goes wrong.
The useful question is not whether a system can fail, but what a failure can cost you.
Here is every case we can name, and what happens to your money in each.
Here is every case we can name, and what happens to your money in each.
IF
Anafi goes offline
THEN
FUNDS STAY PUT
Nothing moves without an engine signature. Your funds stay where they are, owned by you, fully non-custodially.
IF
Execution is delayed
THEN
NOTHING SKIPPED OR ALTERED
Committed rules — on-chain actions can't be skipped or altered. If execution is delayed, funds stay in your wallet or might be processed by licensed partners.
IF
Anafi is asked to hand over your data
THEN
NOTHING TO HAND OVER
There is nothing to hand over. Anafi holds no KYC or banking information, and the committed rule is encrypted — the Anafi team cannot read it either.
IF
You change your mind
THEN
REVOKED IN ONE TRANSACTION
One transaction from your wallet. Instant revocation. You always own your funds.
NOT SEEING YOURS?
These four are the ones we get asked about most. If you have a failure case that isn't here, we would rather walk you through it than have you guess.
Ask a Question
03
AUDITS
Reviewed by people who break
things for a living.
SECURITY AUDIT & PENTEST
SECURITY AUDITOR
INFOSEC PARTNER · PENTEST
SECURITY CONTRIBUTORS
Pashov Audit Group
FULL-SCOPE REVIEW
Core
Enclave runtime
Smart contracts
Backend
Reports are published as they land. Scope and status are stated for each.
04
FAQ
The questions behind the diagram.
Can't find what you're looking for?
Ask the team directly.
Ask the team directly.
Talk to us
Who can move funds from my wallet when I use Anafi?
Only the Anafi engine, and only within the rule you signed. The engine's key lives inside an attested TEE; no one on the Anafi team can use it or move funds outside the flow you authorized.
What can an Anafi policy do, and what can't it do?
A policy can send a set amount to destinations you listed — on-chain, off-chain or via off-ramp — when its conditions are met: a schedule, an incoming deposit, a price move, or a pull request from a third party you authorized.
A policy can't send to unlisted destinations, exceed your caps or frequency, or change after you sign it.
A policy can't send to unlisted destinations, exceed your caps or frequency, or change after you sign it.
What is the attested engine, and what does it see?
The attested engine interprets the rules you commit. It runs in an Intel TDX Trusted Execution Environment, so its code is verifiable and its memory is sealed off from us. It sees your wallet address, destinations, rules and triggers. It does not see or store personal data.
What happens if Anafi goes offline or is compromised?
If Anafi goes offline, execution pauses. Your funds stay in your wallet and you don't need to do anything; missed payments execute once when the engine is back. If Anafi's internal systems are compromised, an attacker still can't reach your funds: the engine key sits in the TEE, and every transfer is bounded on-chain by the rules you signed.
Can Anafi be forced to hand over my data?
We can only hand over what we hold: wallet addresses and execution logs. Your rules are encrypted, and we hold no KYC or banking data — that stays with licensed partners under their own obligations.
What does the off-ramp provider know about me?
Whatever its KYC requires — typically full name, date of birth, ID document and proof of address — plus the bank details you provide for payouts. The provider's privacy policy governs this data, not Anafi's.
How do I revoke a policy?
In the dApp at app.ana.fi: one transaction from your wallet, effective as soon as it's confirmed.
Who reviewed Anafi's security, and what was in scope?
Hexens (full-scope audit, August–October 2026) and Hakira (penetration test). Scope: the engine, backend, compiler, dApp and smart contracts (Solidity and Rust).
KEEP READING
GET STARTED