> For the complete documentation index, see [llms.txt](https://docs.trnch.fun/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.trnch.fun/security.md).

# Security

What TRNCH does to keep you safe, and what you should do too.

## TRNCH never holds your funds

TRNCH is non-custodial. Your tokens stay in your wallet, and your keys never leave it. TRNCH prepares transactions; your wallet shows them and you sign them. Nothing is ever signed automatically on your behalf.

{% hint style="danger" %}
**TRNCH will never ask for your recovery phrase (seed phrase) or your private key.** Not on the site, not by email, not on X, not on Telegram. Anyone who asks is not us. We never ask you to send funds in a private message.
{% endhint %}

## Built-in protections

* Approvals are for the exact amount of the swap, never an unlimited allowance.
* Before each approval, permit or swap, TRNCH checks that your wallet is on Robinhood Chain and asks it to switch. If it stays on another network, nothing is sent.
* Every quote is compared with the other routers' quotes and with a reference price from the token's pools. A quote that cannot be checked gets a maximum slippage of 1%. A quote that loses a large part of its value has to be accepted explicitly.
* A transaction whose ETH amount does not match what you are paying is refused by the server, and checked again in your browser before it reaches your wallet.
* Requests are authenticated and rate-limited, so no one can drain the service's quotas or act in your name.

## Fake tokens are blocked

**TRNCH has no token yet.** Any token using the TRNCH name is not ours.

Tokens imitating TRNCH, lookalike spellings and swapped letters included, never appear on the site: not on the Heat, in the Activity feed, in search or in the swap panel. The same goes for copies of ETH, WETH and USDG that are not the real contracts. A link to such a token opens a short notice, "Not a TRNCH token", instead of a chart or a swap.

## Flagged tokens in your wallet

In **Your wallet**, tokens that look unsafe are folded in a red line, and each one says why: it has no market, it imitates TRNCH, ETH, WETH or USDG, or it shares its ticker with another token you hold while its value doesn't add up. They cannot be sold from TRNCH and are never offered as payment.

## Good habits

* Bookmark trnch.fun and always check the address in your browser.
* Check a token's contract address before you buy. A familiar name or logo proves nothing.
* Start with small amounts on thin pools, and keep your slippage as tight as the pool allows.
* Review your approvals from time to time and revoke the ones you no longer need.
* Use a hardware wallet for significant amounts.
* Ignore private messages offering help, airdrops or "support". Real support only answers where you contacted it.

## Report a problem

Found a fake TRNCH token, a scam or a security issue? Write to <hello@trnch.fun> with the token address or the link, and where you saw it. For a security issue, please tell us before making it public. See [Contact](/contact.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.trnch.fun/security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
