Security and trust model

Control starts with separation of authority

Policies, formal admission, threshold cryptography and protected execution perform different jobs. Their relationships and boundaries are defined by the trust model for each configuration.

Control mechanisms

Effect checks

Estimate changes before signing using the available system state.

Policies and T1

Mandatory organisational restrictions and risk assessment with recorded factors.

Bound admission

Single-use authorisation for a defined cryptographic step of a specific operation.

MPC and HSM

Threshold execution and protected key shares in the agreed cryptographic architecture.

Separate publication

Control transmission of a signed operation to an external network and monitor its result.

End-to-end records

An auditable record accompanies every critical stage. It includes decision grounds, rejections and stops, as well as successfully executed operations.

Applications, agents and cryptographic systems have distinct permissions

Client applications and AI agents hold no key shares. Secret-dependent operations run in an isolated cryptographic environment. Having enough MPC participants does not remove the admission check.

  1. Application / agent: proposes intent
  2. Control: effects, policies, T1, admission
  3. Cryptographic environment: MPC / HSM
  4. Publication and network monitoring

Recovery follows the selected profile

Loss of a node

Continuation depends on retaining the required threshold. The node returns through the agreed procedure.

Loss of the threshold

Protected state, multi-party recovery and a new MPC/HSM environment are used according to the recovery profile.

An unfinished operation

Handling relies on the last reliable state. A completed step must not create a new independent operation; conflicts require a stop.

Recovery conditions and operating parameters are agreed. A universal backup of the complete private key and unconditional availability are not assumed.

Records for review and investigation

Identifiers, configuration, simulation, policies, T1 factors, approvals, cryptographic stages, publication and external status are linked to the operation. Monitoring exports, retention periods, event correlation and access rights are agreed. Secret cryptographic state is not part of an audit export.

Topics for technical assessment

  1. Architecture and independence

    Trust boundaries, participant deployment and access to protected state.

  2. Operation profiles

    Networks, assets, protocols, versions and supported operation types.

  3. Mandatory admission

    Authorisation binding, expiry, retries and potential signer bypass routes.

  4. Changes and failures

    Changes between checking and publication, node and threshold loss, and unfinished operations.

  5. Observability

    Event examples, record access and integration with control systems.

  6. Test conditions

    Load-test configuration, T1 sources and handling of missing data.

Define technical and organisational responsibilities

The resulting protection depends on configuration, participant independence, infrastructure and operating procedures. Owners for policy changes, updates, recovery, publication stops and incident investigation are defined during scoping.

Deployment steps

Further reading

Choose the plan for your next step

Compare monthly plans, included usage and additional costs. Online signup is currently unavailable.