Legal
Trust & Execution Model
Last updated: July 8, 2026
Legal review status: pending external legal review before unrestricted public launch
Does the AI execute automatically?
No. AI can prepare executable actions, but live submission requires the applicable user approval path and must pass policy, venue, signer, and feature-gate checks.
What does manual approval mean?
Manual approval means you review the action details shown in the product before authorizing Mattheus to submit that action or a scoped policy-controlled workflow.
Can execution still fail after approval?
Yes. RPC, protocol, liquidity, gas, market, signer, venue, and policy issues can block, delay, reject, or change the outcome of an approved action.
Summary
Mattheus is a customer-owned multi-asset research and workflow runtime. The platform is being built to research, plan, compose, preview, and prepare Hyperliquid, Alpaca, Uniswap, and Aave actions. All four share one launch gate and remain non-public while the verdict is NO_GO. Users manually approve before live execution, and policy gates may block an action even after it is prepared.
What can the AI do?
AI-assisted workflows may:
- Read market, protocol, portfolio, liquidity, and venue context
- Draft strategies, workflow logic, conditions, and risk summaries
- Create previews for supported Hyperliquid actions
- Prepare executable payloads only for supported, certified, and enabled flows
AI-generated output may be wrong or stale. Review the AI Disclosure before relying on AI output.
What can the AI not do?
AI-assisted workflows should not be described as able to:
- Proceed around user approval, signer readiness, policy gates, feature gates, or venue checks
- Submit live actions without the applicable approval path
- Promise fills, prices, uptime, safety, yield, performance, or outcomes
- Provide individualized investment, financial, tax, or legal advice
What does manual approval mean?
Manual approval means the user must review the action details presented in the product before live submission. Approval copy should stay short and clear: review carefully, confirm the shown details, and understand that market conditions may change before execution.
How do policy gates and limits work?
Policies are intended to bound execution behavior. Depending on the enabled flow, policies may check:
- Market, protocol, asset, or contract allowlists
- Order size, exposure, daily volume, slippage, gas, or liquidation limits
- Signer readiness, subscription state, idempotency, feature flags, and venue health
- Protocol certification for Uniswap and Aave write actions
A policy rejection means Mattheus should not submit the proposed action. Rejection does not itself close an existing position, cancel open orders, or revoke venue permissions.
Venue examples
Venue-specific permissions should be explained only at the level confirmed for that flow.
- Hyperliquid agent wallet - approveAgent readiness, Hyperliquid authorization key readiness, signer readiness, policy checks, and explicit approval are required before supported place, cancel, or close actions proceed. Agent wallets do not hold user funds and can be locally revoked, expired, or rotated.
- Uniswap and Aave actions - protocol writes require certified lifecycle support, wallet readiness, policy checks, action preview, and user approval.
- Deferred venues - any venue not separately enabled should remain labeled as deferred or blocked in product copy.
What execution risks remain?
Approved actions can still fail or settle differently than expected because of:
- RPC, network, signer, venue API, indexer, or infrastructure failures
- Protocol bugs, smart contract bugs, oracle issues, bridge issues, or wallet issues
- Liquidity changes, slippage, gas changes, funding changes, liquidations, or volatile markets
- Policy changes, feature gates, account readiness, stale data, or insufficient balances
Some transactions may be irreversible once submitted. Trading involves risk, including the possible loss of some or all funds committed to a trade or strategy.
How do permissions and revocation work?
Permissions vary by venue and protocol. Mattheus should describe the exact wallet, signing, allowance, API wallet, or venue authorization architecture only where it has been confirmed by engineering and legal. Supported permissions should be revocable where the venue, protocol, wallet, or Mattheus product surface supports revocation. Local stop controls and venue-level revocation are separate states and should both be checked where applicable.
To stop activity, use product stop controls where available, cancel open orders where supported, revoke API keys or AI provider keys from Settings, and confirm venue-level or wallet-level revocation outside Mattheus when that venue or protocol requires it.
Is Mattheus financial advice?
No. Mattheus is software infrastructure. Mattheus does not provide personalized financial, investment, tax, or legal advice. Users are responsible for decisions they approve.
How can I get help?
Product support and legal review contacts are supplied through verified controlled-beta workflows. Read the Risk Disclosure before approving live actions.