Security

Protection against attacks from the outside:

  • The software is Bitcoin-only, reducing complexity and attack vectors.
  • Hard- and software come from a single, reputable source (US-listed and regulated Fortune 500 company), which means:
    • Hard- and software are designed to work together seamlessly.
    • One reputable counterparty is liable for both the hard- and software.
  • The vault is protected by multiple keys. One compromised or stolen key cannot move funds.
  • One key is protected by cold hardware with a screen. That key is never exposed to the internet and the hardware let's the owner verify every transaction before signing.
  • The keys are geographically distributed. Even if the owner were being extorted, they could not transfer funds to the extortionists.
  • The vault uses the native SegWit address format to enhance protection against potential quantum computer attacks in the future.

Protection against attacks from inside the technology/collaborative custody partner:

  • The partner is a US-listed and regulated Fortune 500 company
  • The software is open-source, i.e. the public can examine the software.
  • The partner only controls one key. Not enough to move funds.
  • The partner's key is well-protected by:
    • technical measures
    • operational measures
    • a delay-and-notify procedure – the key does not sign immediately upon request, but it informs the client that it is about to sign, unless the client stops the process

Protection against force majeur:

  • Digital assets are intangible and "stored" on the blockchain, so they are not endangered by nuclear war or natural disasters.
  • The vault is protected by multiple, geographically distributed and backed-up keys. Losing a key in the event of a war or natural disaster poses no danger.