Pistachio Security Overview

Pistachio Security Overview

Pistachio Security Overview

Pistachio Security Overview

Aug 5, 2025

a black mobile phone with a fingerprint on it

Each part of our infrastructure from key management and smart account security to vault integration is designed to meet the highest standards of safety and composability.

Token Storage:

All sensitive tokens are stored using [SecureStore](https://docs.expo.dev/versions/latest/sdk/securestore/), leveraging OS-level encryption (Keychain for iOS, Keystore for Android) to protect credentials at rest.

User Authentication:

Authentication is secured through time-limited, single-use OTPs, preventing credential reuse and minimizing exposure to phishing or brute force attacks.

Funds & App Authentication Separation:

User funds are cryptographically protected independent of app-level authentication. This separation ensures that any compromise of app credentials or sessions does not affect access to assets, recovery mechanisms, or the security of private keys.

On-Device Key Management:

All cryptographic keys are generated or restored securely and stored on-device using native secure enclaves. These keys are never transmitted or exposed outside of the device environment.

Redundant Cloud-Backed Recovery with Liveliness Requirements:

Backup keys are encrypted and stored with Apple iCloud and Google Cloud services. These backups cannot be used in isolation:

  • Breaches from our company do not compromise funds.

  • Breaches of Apple or Google alone are insufficient due to liveliness checks enforced by Pistachio.

  • Breaches of the MPC layer (our third-party cryptographic key custody provider) cannot yield usable keys without simultaneously breaching both cloud providers and bypassing liveliness detection.

Download Today

Download Today

© 2024 Pistachio FI Inc.

x logo
discord logo
youtube logo
linkedin logo

Pistachio is a software platform ONLY and does not conduct any independent diligence on or substantive review of any blockchain asset, digital currency, cryptocurrency or associated funds. Users are fully and solely responsible for evaluating your investments, for determining whether you will swap blockchain assets based on your own, and for all your decisions as to whether to swap blockchain assets with the Pistachio in app swap feature. In many cases, blockchain assets you swap on the basis of your research may not increase in value and may decrease in value. Similarly, blockchain assets you swap on the basis of your research may increase in value after your swap. Past performance is not indicative of future results. Any investment in blockchain assets involves the risk of loss of part or all of your investment. The value of the blockchain assets you swap is subject to market and other investment risks.

Pistachio users are responsible for storing their recovery phrase in their personal cloud. If the recovery phrase is lost, the user might not be able to retrieve their private keys.Because the Software is locally installed, you are responsible for the security of the device on which it is installed, including ensuring that you keep anti-virus software current and otherwise protect the device on which the Software is installed against malware. Pistachio is not responsible for any loss or damages – including loss of funds or lockout from accounts accessed via the Software – resulting from your failure to keep the device on which the Software is installed safe and free of any malware. Pistachio cannot recover passwords or unlock account information stored on the Software in any circumstances, including if the Software is compromised by malware on your computer, and it is your sole responsibility to take all reasonable precautions to secure and backup your copy of the Software and the information stored on it.

We make no warranties or representations, express or implied, about any linked third-party materials available on the Pistachio, the third parties they are owned and operated by, the information contained on them or the suitability of their products or services. You acknowledge sole responsibility for and assume all risk arising from your use of any third-party websites, applications, or resources.


Pistachio does not provide investment or financial advice or consulting services. We are solely the provider of the non-custodial wallet and we do not advise or make recommendations about engaging in digital asset transactions or operations. Decisions to engage in transactions or perform operations involving digital assets should be taken on your own accord.

© 2024 Pistachio FI Inc.

x logo
discord logo
youtube logo
linkedin logo

Pistachio is a software platform ONLY and does not conduct any independent diligence on or substantive review of any blockchain asset, digital currency, cryptocurrency or associated funds. Users are fully and solely responsible for evaluating your investments, for determining whether you will swap blockchain assets based on your own, and for all your decisions as to whether to swap blockchain assets with the Pistachio in app swap feature. In many cases, blockchain assets you swap on the basis of your research may not increase in value and may decrease in value. Similarly, blockchain assets you swap on the basis of your research may increase in value after your swap. Past performance is not indicative of future results. Any investment in blockchain assets involves the risk of loss of part or all of your investment. The value of the blockchain assets you swap is subject to market and other investment risks.

Pistachio users are responsible for storing their recovery phrase in their personal cloud. If the recovery phrase is lost, the user might not be able to retrieve their private keys.Because the Software is locally installed, you are responsible for the security of the device on which it is installed, including ensuring that you keep anti-virus software current and otherwise protect the device on which the Software is installed against malware. Pistachio is not responsible for any loss or damages – including loss of funds or lockout from accounts accessed via the Software – resulting from your failure to keep the device on which the Software is installed safe and free of any malware. Pistachio cannot recover passwords or unlock account information stored on the Software in any circumstances, including if the Software is compromised by malware on your computer, and it is your sole responsibility to take all reasonable precautions to secure and backup your copy of the Software and the information stored on it.

We make no warranties or representations, express or implied, about any linked third-party materials available on the Pistachio, the third parties they are owned and operated by, the information contained on them or the suitability of their products or services. You acknowledge sole responsibility for and assume all risk arising from your use of any third-party websites, applications, or resources.


Pistachio does not provide investment or financial advice or consulting services. We are solely the provider of the non-custodial wallet and we do not advise or make recommendations about engaging in digital asset transactions or operations. Decisions to engage in transactions or perform operations involving digital assets should be taken on your own accord.

© 2024 Pistachio FI Inc.

x logo
discord logo
youtube logo
linkedin logo

Pistachio is a software platform ONLY and does not conduct any independent diligence on or substantive review of any blockchain asset, digital currency, cryptocurrency or associated funds. Users are fully and solely responsible for evaluating your investments, for determining whether you will swap blockchain assets based on your own, and for all your decisions as to whether to swap blockchain assets with the Pistachio in app swap feature. In many cases, blockchain assets you swap on the basis of your research may not increase in value and may decrease in value. Similarly, blockchain assets you swap on the basis of your research may increase in value after your swap. Past performance is not indicative of future results. Any investment in blockchain assets involves the risk of loss of part or all of your investment. The value of the blockchain assets you swap is subject to market and other investment risks.

Pistachio users are responsible for storing their recovery phrase in their personal cloud. If the recovery phrase is lost, the user might not be able to retrieve their private keys.Because the Software is locally installed, you are responsible for the security of the device on which it is installed, including ensuring that you keep anti-virus software current and otherwise protect the device on which the Software is installed against malware. Pistachio is not responsible for any loss or damages – including loss of funds or lockout from accounts accessed via the Software – resulting from your failure to keep the device on which the Software is installed safe and free of any malware. Pistachio cannot recover passwords or unlock account information stored on the Software in any circumstances, including if the Software is compromised by malware on your computer, and it is your sole responsibility to take all reasonable precautions to secure and backup your copy of the Software and the information stored on it.

We make no warranties or representations, express or implied, about any linked third-party materials available on the Pistachio, the third parties they are owned and operated by, the information contained on them or the suitability of their products or services. You acknowledge sole responsibility for and assume all risk arising from your use of any third-party websites, applications, or resources.


Pistachio does not provide investment or financial advice or consulting services. We are solely the provider of the non-custodial wallet and we do not advise or make recommendations about engaging in digital asset transactions or operations. Decisions to engage in transactions or perform operations involving digital assets should be taken on your own accord.