Security
Protection against attacks from the outside:
- The software is Bitcoin-only, reducing complexity and attack vectors.
- Hard- and software come from a single, reputable source (US-listed and regulated Fortune 500 company), which means:
- Hard- and software are designed to work together seamlessly.
- One reputable counterparty is liable for both the hard- and software.
- The vault is protected by multiple keys. One compromised or stolen key cannot move funds.
- One key is protected by cold hardware with a screen. That key is never exposed to the internet and the hardware let's the owner verify every transaction before signing.
- The keys are geographically distributed. Even if the owner were being extorted, they could not transfer funds to the extortionists.
- The vault uses the native SegWit address format to enhance protection against potential quantum computer attacks in the future.
Protection against attacks from inside the technology/collaborative custody partner:
- The partner is a US-listed and regulated Fortune 500 company
- The software is open-source, i.e. the public can examine the software.
- The partner only controls one key. Not enough to move funds.
- The partner's key is well-protected by:
- technical measures
- operational measures
- a delay-and-notify procedure – the key does not sign immediately upon request, but it informs the client that it is about to sign, unless the client stops the process
Protection against force majeur:
- Digital assets are intangible and "stored" on the blockchain, so they are not endangered by nuclear war or natural disasters.
- The vault is protected by multiple, geographically distributed and backed-up keys. Losing a key in the event of a war or natural disaster poses no danger.
