Separate storage from communication

“Stateless” describes a design intended not to retain signing secrets between sessions. “Air-gapped” describes a communication arrangement. These are different properties, and a product may support several operating modes. Do not infer either property from a brand name alone.

Read the current documentation for the exact device, software and selected mode. Identify where secrets are loaded, how transactions arrive, what the device displays for approval and what storage remains after use. A statement about normal operation is not proof that malicious firmware could not behave differently.

Transient keys still need protection during use

A signer that does not intentionally retain a seed can reduce one kind of exposure after normal shutdown. It does not protect a seed photographed during loading, a compromised software image or an unsafe backup. Do not promise that every trace disappears instantly or that the architecture is immune to physical or supply-chain attacks.

QR communication also needs careful handling. A QR code can contain a transaction, public configuration or a full secret, depending on its format. Label and protect it accordingly. Do not assume a SeedQR is merely a harmless wallet descriptor, or place a secret-bearing image in a general handoff.

Practise the actual workflow

Use a separate empty test wallet to learn setup and signing. Confirm how to authenticate software, inspect transaction details and stop when something differs from the expected process. Keep live recovery material away from public websites and unsolicited support contacts.

For the intended recipient, document the exact product, configuration, official instructions and backup location. Consider whether repeatedly loading a secret is a process they can manage safely. More manual steps can introduce mistakes even when the underlying architecture serves a useful purpose. Record what was tested and review after a device or software change.

Preserve independent recovery instructions

ZeroLatch can deliver a scoped inventory and instructions after a missed check-in and safety period. It does not transfer assets, establish legal authority or confirm death. Simple permits authorised service-managed key recovery; Private requires a separate password or ZeroLatch recovery phrase. Neither option replaces an independent backup or a real recipient rehearsal. Start with harmless information and read the security model and backup checklist.

A conditional message can tell the recipient where to find the device instructions and whom to contact. It should not be the only place a backup exists. The appropriate signing architecture depends on the whole custody arrangement, including people and recovery, rather than a simple ranking of stateless and persistent devices.