Skip to Content

Trust & Security

The Vault is custody infrastructure. Trust is not a marketing claim — it is something you should be able to verify. This page collects the independent assessments we are pursuing, the controls already in place, and the technical artifacts we share — our security posture openly, and the full specifications under NDA — so you do not have to take our word for any of it.

Status at a glance

ItemAuditorStatus
SOC 2 Type IKirkpatrickPrice 🟢 Report available
SOC 2 Type IIKirkpatrickPrice 🟡 In progress
ISO/IEC 27001Hacken 🟡 In progress
MPC protocol auditHalborn 🟢 Report available
Server signer auditHalborn 🟢 Report available
Mobile signer auditHalborn 🟡 In progress
Penetration testDeloitte 🟡 In progress
MPC security model (overview)🟢 Public
Architecture documentation🟢 Public
Threat model🔒 Under NDA
Full protocol specs & DR runbooks🔒 Under NDA
Continuous internal red teamThe Vault Security🟢 Active
Bug bounty program⚪ Planned

Final reports are made available under NDA to qualified prospects and customers. See Request reports below.

What you can verify today

We publish our security model and architecture openly at a posture level. The full protocol specifications, threat model, and operational runbooks are shared under NDA with qualified prospects and customers.

Cryptographic foundations

The Vault uses threshold MPC. No single party — including The Vault itself — holds a complete private key at any point in a wallet’s lifecycle.

  • Threshold scheme. Default 3-of-4; configurable per deployment.
  • Protocols. Distributed Key Generation, threshold signing, proactive share refresh, and verifiable recovery. The protocol-level detail lives in the MPC security model.
  • Key share storage. Mobile signer shares are stored encrypted at rest in the device’s secure storage; the encryption key is held in the OS secure storage (iOS Keychain / Android Keystore, hardware-backed — StrongBox / Secure Enclave — where the device provides it).
  • Confidential computing. When TEE mode is enabled, the server signer workloads run in hardware TEEs (Intel TDX) with remote attestation before any key share is delivered. The coordinator holds no key material and runs as a standard service.
  • Transport security. All inter-service traffic uses mutual TLS. MPC signer-to-signer messages are end-to-end encrypted with the Noise Protocol, relayed through the coordinator, which cannot read them.
  • Audit integrity. Every privileged action writes to a hash-chained, append-only audit log.

The full cryptographic specification is the subject of the Halborn MPC and Mobile Signer audits currently in flight.

Compliance & data handling

TopicStatus
Data residencyConfigurable per deployment — see Deployment Sovereignty
Sub-processorsList in preparation — available on request
Privacy / DPAAvailable on request
Penetration testingContinuous internal red-team coverage; external pen test scheduled post-SOC 2 Type I
Blockchain screeningOn the roadmap — see below
InsuranceUnder evaluation

Roadmap

We update this page whenever a milestone moves.

Request reports

The following are available under NDA to qualified prospects and customers:

  • SOC 2 Type I report
  • Halborn audit reports — MPC protocol and Mobile signer (once published)
  • Penetration test summary
  • Data Processing Agreement
  • Sub-processor list
  • Architecture brief

Contact our team to receive the reports you’re interested in.