Keys & Policies

Transactions secured by MPC. Enforced by policy. Running inside your security perimeter.

MPC secured custody across hot, warm and cold configurations, with signing performed in hardware isolated secure enclaves and policy enforced at the cryptographic layer. Components designed to be operated by institutions inside their cloud or data center.

No single point of compromise

With Multi-Party Computation (MPC), your private keys never exist in one place.

Individual nodes running in attested secure enclaves generate key shares using our battle-tested algorithm. The complete key is never assembled or exposed in any single location.

Generation

Key shares are generated independently by each node at the exact same time. Because the nodes cooperate to create the shares without ever combining them, the complete master key never exists in any single location at any point.

Signing

Once a transaction is submitted for signing, the threshold number of nodes must participate, each contributing its share to a joint computation. The key is never assembled in any single location.

Rotation

Rotation is performed through distributed computation across the nodes. New shares are generated across the nodes and rotation schedules are configurable per account. Each event is logged with multi-party authorization.

Backup & Recovery

Recovery requires participation from multiple parties with no single operator able to execute a recovery. The full procedure is recorded in the audit trail.

MPC secured policies

Our flexible policy engine is cryptographically enforced at each individual node and linked to the signing process.

Policy controls extend our no-single-point-of-compromise standard and all parsing and validation happen in secure enclave environments.

Value Caps

Transactions above a defined value escalate to a higher approval tier automatically.

Counterparty Controls

Whitelist approved counterparty addresses at the account level and block transactions to unlisted addresses before signing.

Network Restrictions

Limit which networks a given account or operator can transact on. Enforced before the transaction reaches the signing layer.

Operational sovereignty

Built for institutions that value complete and exclusive control over their keys, policies, and wallet operations.

Components are designed to be deployed in your cloud of choice or in your data center. Our dedicated professional services team provides the support required to get up and running quickly.

Initiator

Creates and submits transactions and sets the parameters of asset, amount, counterparty and network. Initiators cannot approve their own transactions.

Approver

Reviews transactions submitted by the initiator and approves or rejects. The approver identity and timestamp are recorded in the audit trail.

Threshold

For high-value or high-risk transactions, multiple approvals can be configured as a requirement before signing can proceed.

get started

Connect with our Institutional Team

Tell us about your market access and infrastructure requirements. Our team will be in touch to help you implement the right solutions for your institution.

Select all that apply

By clicking ‘Submit’, you agree to share your information with Blockdaemon to receive marketing, updates, and other emails. Use the unsubscribe link in those emails to opt-out at any time.

Thanks for submitting the form.