Reviewing a Wallet's Documentation
What good documentation contains, what its absence indicates, and the five pages worth reading before trusting any wallet.
Documentation quality correlates with software quality more reliably than any other signal we have found. It is also free to check before installing anything.
The five pages worth reading
The security model. Where keys are generated and stored, what the wallet has access to, what it sends to servers. A wallet that does not document this has not thought about it or does not want you to.
Recovery. Whether the wallet uses a standard recovery phrase, which derivation path it uses by default, and how to restore elsewhere.
The derivation path is the detail that matters and it is rarely documented. Its absence causes the most common confusing restore failure.
The default endpoint. Which provider the wallet queries by default and whether it can be changed. Many wallets do not say.
The audit history. Which firm, when, covering what, with findings and their resolution. An audit of an old version, or of a component, is a partial answer presented as a complete one.
The update policy. How updates are delivered and whether release notes are published.
What absence indicates
A wallet with no security model documentation, no stated derivation path and no audit history is asking for trust without providing anything to evaluate.
That does not make it bad software. It makes it unassessable, which for something holding value is a reasonable basis for choosing something else.
What good looks like
Specific rather than reassuring. “Keys are generated on device using the platform secure enclave and never transmitted” is a claim you can evaluate. “Bank-grade security” is not.
Documentation that states limitations is a stronger signal than documentation that does not. A wallet explaining what its threat model does not cover is one whose authors have thought about it.
The recovery documentation test
Can you, from the documentation alone, restore this wallet in different software?
If yes, you are not locked in and the developer’s continued existence does not determine your access. If no, you are depending on a company for years.
That is the single most important question about any wallet and it is answerable from the documentation in five minutes.
The venue equivalent
For a platform rather than a wallet, the three documents are the listing policy, the fee schedule and the terms covering insolvency.
Venues publishing all three without requiring an account, such as a platform we ran a full withdrawal through, have made the assessment possible before you commit anything. Where any of the three requires registration to read, that is itself the answer.
Products covered here are bought at full retail price and used for real transactions before anything is written. There are no affiliate links on this site, no sponsored placements and no review units. If that ever changes, it will be disclosed at the top of the article.