← Home

A Third Way

Keep your keys close.

Self-custody needs a signing device. A phone wallet keeps that authority on the phone, where attackers have the most ways to reach you. A dedicated wallet moves it to another device, one that is easier to misplace and can signal what you hold. Cryptograph keeps it on your Apple Watch.

The Choice

Where the keys live.

Where the keys live determines what an attacker must compromise.

01 · Phone wallet

On the phone

The keys share a device with the apps, links, messages, and networks you use every day.

02 · Dedicated wallet

On another device

A purpose-built wallet separates signing from the phone. It is another object to carry, and another object for attackers to notice.

03 · Cryptograph

On your Apple Watch

Your Apple Watch holds the keys and signs. It does not browse links, connect to dApps, or handle outside network traffic. Phishing and malware on your iPhone stay outside the signing boundary. Your iPhone cannot sign.

Cryptograph's Design

Keys stay on your Apple Watch.

In Cryptograph, your Apple Watch is the only device that can approve and sign. Your iPhone displays requests and handles the outside world.

Your Apple Watch · Signing authority
  • Creates and holds the wallet
  • Shows transaction details before approval
  • Approves and signs transactions
  • Encrypts recovery data before export
Your iPhone · Display and transport
  • Shows the portfolio and prepares requests
  • Handles WalletConnect and network traffic
  • Relays requests and completed signatures
  • Cannot sign
Secure Enclave

Your keys are secured by the Secure Enclave on your Apple Watch. The encrypted wallet is protected there by a hardware key that cannot be exported.

Tradeoffs

What you trust.

Cryptograph relies on the hardware in your Apple Watch, watchOS, App Store distribution, and Cryptograph itself when you sign. Dedicated wallets make different choices.

Already with you

No dedicated crypto object in a drawer, pocket, or bag. Approval happens on your Apple Watch.

Apple platform

Cryptograph requires a compatible Apple Watch and iPhone. Signing runs in Cryptograph on your Apple Watch, not inside a purpose-built secure element.

Approval on the wrist

Your Apple Watch displays consequential transaction details before approval becomes available. Your iPhone cannot approve on its own.

Recovery, by design

Setup includes an encrypted Recovery Sheet. Photo Backup can provide a second encrypted copy. Cryptograph has no recovery backdoor.

If your Apple Watch is lost or replaced, restore on another compatible Apple Watch. If your Apple Watch and every recovery copy are lost, the funds cannot be recovered. Read the recovery guide.

Questions

Self-custody on Apple Watch.

How do I keep my crypto private keys off my iPhone?

Use a separate signing device. A dedicated wallet is one option. Cryptograph keeps the keys and approval on your compatible Apple Watch while your iPhone handles display and networking.

Is Apple Watch a hardware wallet?

With Cryptograph, your Apple Watch is the wallet's signing device. Keys are secured by the Secure Enclave, and approved transaction signing happens in Cryptograph on watchOS.

Is Cryptograph a Ledger or Trezor alternative?

Cryptograph is a different architecture for people who already wear a compatible Apple Watch.

Cryptograph Watch Wallet

Your keys on your wrist.

See how Cryptograph works or review the full security architecture.

View in the App Store