Effect checks
Estimate changes before signing using the available system state.
Security and trust model
Policies, formal admission, threshold cryptography and protected execution perform different jobs. Their relationships and boundaries are defined by the trust model for each configuration.
Estimate changes before signing using the available system state.
Mandatory organisational restrictions and risk assessment with recorded factors.
Single-use authorisation for a defined cryptographic step of a specific operation.
Threshold execution and protected key shares in the agreed cryptographic architecture.
Control transmission of a signed operation to an external network and monitor its result.
An auditable record accompanies every critical stage. It includes decision grounds, rejections and stops, as well as successfully executed operations.
Client applications and AI agents hold no key shares. Secret-dependent operations run in an isolated cryptographic environment. Having enough MPC participants does not remove the admission check.
Continuation depends on retaining the required threshold. The node returns through the agreed procedure.
Protected state, multi-party recovery and a new MPC/HSM environment are used according to the recovery profile.
Handling relies on the last reliable state. A completed step must not create a new independent operation; conflicts require a stop.
Recovery conditions and operating parameters are agreed. A universal backup of the complete private key and unconditional availability are not assumed.
Identifiers, configuration, simulation, policies, T1 factors, approvals, cryptographic stages, publication and external status are linked to the operation. Monitoring exports, retention periods, event correlation and access rights are agreed. Secret cryptographic state is not part of an audit export.
Trust boundaries, participant deployment and access to protected state.
Networks, assets, protocols, versions and supported operation types.
Authorisation binding, expiry, retries and potential signer bypass routes.
Changes between checking and publication, node and threshold loss, and unfinished operations.
Event examples, record access and integration with control systems.
Load-test configuration, T1 sources and handling of missing data.
The resulting protection depends on configuration, participant independence, infrastructure and operating procedures. Owners for policy changes, updates, recovery, publication stops and incident investigation are defined during scoping.
Deployment stepsDefine the configuration, responsibilities and pilot checks.
Read guideFollow intent, checks, admission, signing, publication and external status.
Read guideCompare monthly plans, included usage and additional costs. Online signup is currently unavailable.