XColdPro Security Architecture
How XColdPro isolates keys, what its encryption does and does not cover, and the operating assumptions the design depends on.
Encryption
Wallet material is stored under AES-256-GCM, an authenticated cipher, so tampering with the stored data is detected rather than silently accepted.
Air-gap isolation
Severing network paths — WiFi, Bluetooth, Ethernet — removes the remote attack surface. Keys are generated and used only inside that isolated environment; only unsigned and signed transaction data crosses the boundary.
What this cannot protect against
Software-first cold storage protects key material through software controls on hardware you supply. It does not defend a device that is already compromised before the wallet is created, and anyone holding the seed can spend outside XColdPro. Cold storage is a set of controls, not an absolute.