Security
Protection against attacks from the outside
The software is bitcoin-only, reducing complexity and attack vectors.
- Hard- and software come from a single, reputable source (US-listed and regulated Fortune 500 company), which means:
- Hard- and software are designed to work together seamlessly.
- One reputable counterparty is liable for both the hard- and software.
- The vault is protected by multiple keys. One compromised or stolen key cannot move funds.
- One key is protected by cold hardware with a screen. That key is never exposed to the internet and the hardware let's the owner verify every transaction before signing.
- The other key is stored in the
- keystore of a dedicated smartphone that only connects to the internet to update software and verify or broadcast transactions.
- in the cloud in an encrypted form.
- The keys are geographically distributed, providing geo-redundancy. Even if the owner were being extorted, they could not transfer funds to the extortionists.
- The keys can be stored in EMP (electromagnetic pulse) protected vaults.
- The vault uses the native SegWit address format to enhance protection against potential quantum computer attacks in the future.
Protection against attacks from inside
Technology/collaborative custody partner:
- The partner is a US-listed and regulated Fortune 500 company
- The software is open-source, i.e. the public can examine the software.
- The partner only controls one key. Not enough to move funds.
- The partner's key is well-protected by:
- technical measures
- operational measures
- a delay-and-notify procedure – the key does not sign immediately upon request, but it informs the client that it is about to sign, unless the client stops the process
Recovery contact(s):
- A recovery contact only holds the key necessary to help the owner decrypt their cloud backup key. Recovery contacts never hold any vault keys.
- The technology partner's software secures the recovery contact's decryption key. In other words, the recovery contact does not need to be tech-savvy.
- To improve operational continuity, more than one trusted recovery contact may be appointed.
Beneficiaries:
- Although beneficiaries can initiate the inheritance process at any time, a mandatory six-month security period begins, during which the owner is alerted.
- The beneficiary will only get possession of vault keys after the expiration of that period.
Protection against force majeur
- Digital assets are intangible and "stored" on the blockchain, so they are not endangered by nuclear war or natural disasters.
- The vault is protected by multiple, geographically distributed and backed-up keys. Losing a key in the event of a war or natural disaster poses no danger.
Continue to read on why this setup also provides privacy.
