Twix Games / Security

Beautiful clients. Hard boundaries.

Twix Games treats the Unity client as an interface — not as the ultimate source of authority. Financial actions should remain subject to signer authorization and on-chain enforcement.

CLIENTuntrusted presentation surface
SDK COREvalidated application interface
SIGNERuser authorization boundary
CHAINfinal rules and settlement
Design principles

Assume the client can be inspected, modified or replayed.

Security improves when sensitive authority does not depend on keeping ordinary client code secret.

No seed phrases in game logic

Game code should request signatures through a signer interface rather than collecting or persisting mnemonic phrases.

No production secrets in builds

API credentials, privileged contract keys and server secrets should not be compiled into distributable Unity binaries.

On-chain authorization

Critical permissions and asset rules belong in contracts or chain modules, not in UI assumptions.

Transaction simulation

Where supported, preview transaction effects and validate expected targets before a user is asked to authorize value-moving actions.

Module permissions

Third-party extensions should receive declared capabilities, not unrestricted access to the host process or wallet.

Package provenance

Signed packages, hashes, version pinning and reproducible release metadata help users understand what code they are running.

Module trust

“Request signature” is a capability. “Take wallet” is not.

The module model is designed so a useful extension can prepare an operation while the host and signer retain authority over approval.

✓Read-only data capabilities can remain low risk.
✓Write operations pass through explicit transaction construction.
✓Signature requests remain visible and attributable to the requesting module.
✓Modules can be disabled or revoked without changing wallet keys.
Permission boundaryConcept
market.read                 ✓
chain.read                  ✓
wallet.address.read         ✓
transaction.prepare        ✓
transaction.request_signature ✓

wallet.private_key             NOT A CAPABILITY
wallet.seed_phrase             NOT A CAPABILITY
Operational posture

Security is a process, not a badge.

Does using Unity make the terminal automatically secure?

No. A mature engine provides a strong application foundation, but the application still requires secure architecture, dependency management, patching, code signing, secrets management and testing.

Can the client itself be trusted to protect assets?

It should not be the only protection. Asset ownership and critical authorization should be enforced by wallet signatures and blockchain rules wherever possible.

What happens when a module needs to move value?

It should prepare a clearly scoped operation and route the request through the terminal's authorization layer. The user or approved signer decides whether to sign.

Will Twix Games audit third-party modules?

A future registry can expose provenance, signatures, hashes and audit status, but those fields must remain distinct so users can tell signed, reviewed and independently audited software apart.