> For the complete documentation index, see [llms.txt](https://conso-1.gitbook.io/conso/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://conso-1.gitbook.io/conso/pocket/security-and-safety.md).

# Security & Safety

Pocket involves assets and value flows. Use the checks below to reduce account risk and avoid common mistakes.

Pocket is Conso’s asset hub, covering different custody modes (Vault, Wallet, and future Connect Wallet). Security is a shared responsibility: Conso can provide safeguards, but your Telegram account hygiene and transaction discipline matter just as much.

This page focuses on practical steps that prevent the most common loss scenarios.

<details>

<summary><mark style="color:$primary;"><strong>Protect your Telegram account</strong></mark></summary>

Your Conso identity is tied to your Telegram account. If someone takes over your Telegram account, they may also gain access to your Conso session.

**Recommended actions**

* Enable Telegram Two-Step Verification (password + code)
* Review Active Sessions / Devices regularly
* Never share Telegram login codes with anyone
* Be cautious with “support” DMs—Telegram impersonation is common in Web3

**If you suspect compromise**

* Terminate unknown sessions immediately
* Change your Two-Step Verification password
* Move sensitive actions to a trusted device only

</details>

<details>

<summary><mark style="color:$primary;"><strong>Understand custody modes before moving value</strong></mark></summary>

Pocket is designed to support multiple wallet modes. Each has a different security model.

**Vault (Custodial)**

* Designed for low-friction in-app actions
* Custody is managed under Conso’s Vault model
* Treat access control and account security as critical

**Wallet (Self-custody) — when launched**

* You control keys; you are responsible for backup and recovery
* Losing keys or recovery materials typically means permanent loss

**Connect Wallet (Planned)**

* You keep custody in your external wallet
* Safety depends on your external wallet security and approvals

Rule of thumb: use the custody mode that matches your risk tolerance and operational maturity.

</details>

<details>

<summary><mark style="color:$primary;"><strong>Beware of impersonation and “urgent” requests</strong></mark></summary>

**The most common Web3 scam patterns:**

* Look-alike accounts (same avatar/name, similar username)
* Fake admins claiming “wallet issues” or “manual verification”
* Pressure tactics (“limited time”, “urgent”, “your funds will be frozen”)

**Conso will never ask you for**

* Telegram login codes
* Two-Step Verification password
* Seed phrase / private key (for self-custody wallets)
* Remote access to your device

</details>

<details>

<summary><mark style="color:$primary;"><strong>Use beta features with caution</strong></mark></summary>

Vault features may be in beta and limited by whitelist. During beta phases:

* Expect safeguards and rules to evolve
* Start small if you’re testing a new flow
* Keep records (tx hash / screenshots) if you need support

</details>

<details>

<summary><mark style="color:$primary;"><strong>Use beta features with caution</strong></mark></summary>

Vault features may be in beta and limited by whitelist. During beta phases:

* Expect safeguards and rules to evolve
* Start small if you’re testing a new flow
* Keep records (tx hash / screenshots) if you need support

</details>

***

#### FAQ

<details>

<summary><mark style="color:$info;">Is Pocket safe?</mark></summary>

Pocket is designed with safety in mind, but your security depends heavily on Telegram account protection, device hygiene, and address verification.

</details>

<details>

<summary><mark style="color:$info;">Does Conso support seed phrases today?</mark></summary>

Vault does not require seed phrases. Self-custody Wallet will introduce key management when launched; this documentation will be updated accordingly.

</details>
