We never hold the keys, and that is the product
Key management and signing policy for institutions, deployed in your own environment with every approval written to an audit log you control.
What it is, and what it deliberately is not
The second list is shorter and more useful.
Narrow on purpose
The failures in this category are almost never cryptographic. They are operational — one person able to approve their own transfer, a key held by a vendor who became the single point of failure, an audit log nobody could read afterwards. So the platform manages keys, enforces a policy your own people write, and records approvals somewhere you control. That is all it does.
Not a custodian
We never hold a key or a balance. If we vanished tomorrow the keys would still be yours and the policy would still be enforced, because both live in your environment.
Not an exchange
No order book, no matching, no market data. The platform signs what your policy permits and refuses what it does not.
No yield product
Nothing here has a return attached to it, which rules out most of what this industry sells and all of what it apologises for afterwards.
The platform
Three components. Each runs in your environment and none phones home.
Threshold keys, hardware-backed
Keys are generated and stored across a threshold scheme so no single machine or person ever holds a complete key, and the shares sit in hardware security modules you own. Recovery is a documented ceremony with named participants rather than an escrow arrangement with us. We have no ability to sign on your behalf, which is a limitation we would not remove if we could.
Rules your own people write
Amount thresholds, destination allow-lists, time windows and four-eyes approval, expressed as a policy file that lives in your version control and is reviewed like any other code. The engine refuses anything the policy does not permit, and it refuses by default — a policy that fails to parse blocks signing rather than falling open.
Append-only, and yours
Every request, approval, refusal and policy change written to an append-only log in your own storage, with a hash chain a third party can verify without us. The most common thing an auditor asks for is who approved a transfer eighteen months ago, and the most common answer in this industry is a screenshot.
Three audits, published, including the findings
Every review we have commissioned is published in full — including the two medium-severity findings from the 2023 review and the dates they were closed. A security page that carries only a logo is telling you an audit happened rather than what it said, and in this category that distinction is the whole point. The reports are linked rather than summarised, because a summary written by the vendor is a marketing document.
Break it in staging before you trust it
We will give you an environment and a list of the things worth trying to break, including the two that have caught us out before. An evaluation that only tests the happy path has tested nothing.
Talk to engineering
Not to a salesperson. The first call is with somebody who has written part of this, and if your problem is better solved without us they will say so — several have been.