I have had a review of the App, and RPC code, and it looks like the private key from the app is being sent to the public RPC raw transaction endpoint (So, the app is not signing transactions)
I’m hoping I’m wrong, and maybe I missed something…!
Can anyone confirm or deny?