The specific contracts, permissions and pinned arguments that enforce it, written out in full, including the limitations we would rather you heard from us.
Your funds sit in a smart contract wallet you own. Fonte holds a permission scoped to named functions with pinned arguments, enforced on-chain. It cannot send your money anywhere except back to you, and you can revoke it without our cooperation.
Security pages are usually a list of adjectives. This one is a list of specifics, because the whole argument for a non-custodial manager rests on things you can verify rather than things we assert. Where something is a genuine limitation, it is written down here too.
A Safe smart contract wallet, version 1.4.1. Safe is the most widely used smart contract wallet in Ethereum and secures a very large share of on-chain assets. Yours is deployed on Base and you are its owner. Not a sub-account, not a share of a pooled vault. A distinct contract with your address on it.
A Zodiac Roles modifier sits alongside the Safe. Its only job is to hold roles and check every transaction against them before the Safe executes anything. Roles name a target contract, a function selector, and optionally constraints on individual arguments. Anything not explicitly permitted is rejected, because the default is deny.
The software that runs the strategy. It holds a role on the modifier, not a key to your wallet, and it is not an owner of your Safe.
Enough to run the strategy and nothing beyond it: supply and withdraw USDC on Aave, swap between the assets the strategy holds, provide liquidity on the venues it uses, and rebalance between them.
It has exactly one permission that moves USDC out of your vault to a third party, and that is the fee sweep. It is USDC.transfer, selector 0xa9059cbb, with the recipient argument constrained to a single fixed address, the Fonte fee wallet.
That constraint is checked on-chain on every call. A transaction attempting to send your USDC to any other address does not execute. Not "is not permitted by policy". Does not execute.
The fee sweep's amount is not capped by the contract. It is bounded by the fee that has actually been earned, which is enforced in our software rather than on-chain. A compromised keeper could therefore sweep more than it should to the fee address, though it still could not send funds to an attacker's own address. We would rather write that down than let you discover it.
Withdrawal is a separate role with two entries, both single calls, both pinned to you:
withdraw(asset, amount, to), selector 0x69328dec, with asset constrained to USDC and to constrained to your address. This unwinds your lending position straight to you.transfer(to, amount), selector 0xa9059cbb, with the recipient constrained to your address.Because both destinations are pinned to you, a holder of this role can only ever pull funds to themselves. It cannot rebalance, swap, borrow, approve, or batch calls together. It does exactly one job.
There is no notice period, no lock-up, no withdrawal fee, and no approval step on our side. We pay the network fee for you.
Two options, and both are self-custody.
A passkey. A keypair generated inside your device's secure element, used with Face ID or a fingerprint. The private key cannot be extracted, cannot be screenshotted, and cannot be phished, because there is nothing to type. A small on-chain signer contract verifies the signature using Base's native P-256 precompile. There is no seed phrase to type day to day; you save one 12-word recovery key as a backup when you create your vault. The trade-off is covered honestly in our guide to passkeys.
Your own wallet. If you already use a crypto wallet, connect it and it owns the Safe directly.
The strategy interacts with Aave for USDC lending and Aerodrome for liquidity on Base. Both are long-lived, heavily audited, and hold very large amounts of value, which means they have been under adversarial scrutiny for a long time.
This is a deliberate constraint rather than a preference. The highest advertised yields in crypto consistently come from young, unaudited contracts, and the reason they pay more is that they are more likely to fail. We would rather earn a defensible rate somewhere durable.
A security page that only lists strengths is marketing. The real residual risks:
Losing money. Non-custodial is a statement about control, not returns. The strategy can be wrong and you can lose money, including a lot of it in a crypto drawdown.
Smart contract risk. Your funds depend on the correctness of the Safe, the Roles modifier, and every protocol the strategy touches. Those are third-party contracts, widely used and independently audited, which is a strong track record rather than a proof. If you use a passkey, you also depend on our own signer contract, which is ours and has not been independently audited. It holds no funds, but it does decide whether a signature is valid.
Value leaking through permitted actions. A compromised keeper cannot steal to its own address, but it could churn your portfolio through allowed trades and cost you money in fees and slippage. Scoping bounds the worst case; it does not make it zero.
Chain risk. Base operating correctly is a dependency.
Your own device. Someone with your unlocked phone and your biometrics can sign as you. That is true of your banking app too, and it is worth stating.
Everything above is public on Base. Your Safe address, the modifier address, and every permission entry can be read directly from the contracts on a block explorer. You can confirm who owns your Safe, which selectors the keeper role permits, and which arguments are pinned, without asking us and without taking our word for any of it.
If you want the short version of the check, find the permission that moves funds and look at whether its destination is constrained. That one detail tells you most of what you need to know about any company making this claim, including this one.