Your keys.
Your funds.
A wallet you hold, used to pay merchants directly on-chain. The seed phrase is generated on your device and stays there. NATIO gets an extended public key so it can watch for incoming payments — which is enough to tell you a payment arrived, and not nearly enough to move it.
“Non-custodial” is a claim about what we cannot do.
Plenty of services call themselves non-custodial and still hold a key that can move your balance. The distinction that matters is not policy but capability, so here is exactly what changes hands.
- Derive watch addresses
- From the extended public key you share, NATIO can generate a fresh receiving address per invoice. Addresses only.
- Read the chain
- It watches those addresses for incoming transactions and counts confirmations against a public node.
- Tell you what happened
- It records the payment, matches it to an invoice and emits a signed webhook. This is bookkeeping, not control.
- Move your funds
- Spending requires a private key. NATIO never receives one, so there is no request, court order or breach that produces a transfer.
- Freeze a balance
- Your balance lives on a public chain in addresses only you can spend from. NATIO can stop serving you; it cannot stop your money.
- Lose your wallet for you
- If NATIO shuts down, your seed phrase still opens the same wallet in any standard client. Nothing about recovery depends on us existing.
What actually leaves your device.
Non-custody is worth little if the surrounding service quietly collects everything else. These are the four answers that decide how much trust the product needs.
- What is generated on your device
- The seed phrase and every private key derived from it. They are produced in your browser or app and are never transmitted.
- What NATIO receives
- An extended public key (xpub). It allows address derivation and balance watching, and nothing else — it is mathematically incapable of signing.
- What NATIO stores about you
- Account identifier, the xpub, derived addresses, and observed on-chain transactions. No seed, no key, no document images.
- Where verification data goes
- To Didit, the identity provider, when a jurisdiction requires it. NATIO keeps the decision and a reference, not your passport scan.
Verification only where the law asks for it.
Holding your own keys does not exempt anyone from the rules that apply to the service connecting you to a merchant. Where verification is required, it runs through Didit and stays there.
Keeping identity documents is a liability, not an asset. Every copy is a breach waiting for an occasion, and once you hold one you inherit the obligations that come with it. The design here is deliberate: the platform learns whether you passed, when, and under which provider reference — enough to answer a regulator, and nothing that is worth stealing.
Sanctions and watchlist screening runs on the platform side against published lists, on the account and on counterparties. That part is not optional and does not depend on which jurisdiction you are in.
- 1 · Triggered by rule
- A jurisdiction, an amount threshold or a merchant's own policy asks for verification. Nothing is requested speculatively.
- 2 · Performed by Didit
- You complete the check with the identity provider directly. Documents and biometrics go to them, not to NATIO.
- 3 · Recorded as a decision
- NATIO stores the outcome, the provider's reference and the time. A later audit can prove the check happened without the platform holding the evidence.
Where this is today.
The orchestration platform behind NATIO is built and running. The wallet layer described on this page is not — and we would rather say so than let a landing page imply otherwise.
Built and running
Designed, not shipped
Depends on decisions
NATIO is a payment technology platform. It is not a bank, an acquirer, a payment institution or an electronic money institution, it holds no such licence, and it does not accept or hold customer funds. Anything on this page describing the wallet layer is a description of what is being built.
Want to be told when it opens?
Leave a line about what you are building and which markets you care about. That shapes what gets implemented first far more than a waitlist counter does.