D20
AENET Wallet Boundary
AENET Cloud reads only the sanitized wallet snapshot. Below the private boundary, the wallet domain (node, ledger, treasury) prepares unsigned PSBT intents; the machine layer observes readiness; and the signing boundary hands unsigned intents to an external hardware signer. There is no live path from the public web into the wallet runtime.
- AENET Cloud→Public snapshotpublic pages and read-only API read public-data/wallet/ only
- Public snapshot→AENET WalletPRIVATE BOUNDARY — verified export only, one way
- AENET Wallet→Node / Ledger / Treasurywallet domain manages receive and transfer-intent state
- Wallet domain→Unsigned PSBTintents are prepared unsigned
- Unsigned PSBT→External signerSIGNING BOUNDARY — physical confirmation on the hardware signer
- Public side→AENET Walletforbidden: no proxy, no live query, no control