Overview
Live custody position, control state, and platform health.
Vault position
Available balance vs recoverable fees & taxAvailable to convert
—
Recoverable fees & tax Recoverable
—
Total after refund
—
Assets under custody
—
Custody quorum
—
Audit chain
—
Awaiting action
—
Settlement volume
Last 7 days · USDAllocation
—USD
Recent activity
—Platform health
MPC schemeShamir · secp256k1
Quorum—
Audit records—
Chain integrity—
Second factor—
Policy engine enforces ordered rules with no implicit allow. Every write is
attributed to an operator and appended to the hash chain.
Accounts under custody
Balances held in segregated custody accounts.
Ledger accounts
—| Account | Reference | Type | Asset | Balance | Recoverable |
|---|
Transactions
Full lifecycle from creation through policy, approval, signature, and settlement.
—
| ID | Created | Type | Amount | Status | Approvals | Operator | Rail ref |
|---|
Convert & settle
Move approved and signed balances to the settlement rail.
Create withdrawal
Policy runs at creation. The rule whose condition matches first decides the
approval count, signer quorum, and cooling period — there is no implicit allow.
Start conversion
Conversion debits the source account exactly once and submits the transaction to the
external rail. Confirm the destination before proceeding.
Requires the policy approvals, cooling period, and signer
quorum to be complete.
Policy engine
Ordered rules — the first matching condition governs the transaction.
Rule set
No match → denyHow it evaluates
Destinations
Whitelisted settlement endpoints. Only whitelisted destinations are eligible.
Destination whitelist
—| Label | Rail | Address | Status |
|---|
Signers
Key shares participating in the custody quorum.
Quorum shares
—| Signer | Share | Attestation key |
|---|
Audit & activity
Immutable, hash-chained record of custody operations.
Activity
—Chain integrity
Status—
Records—
DigestSHA-256
SealingPBKDF2-HMAC-SHA256 · 200k
SignatureEd25519 · RFC 8032
Key splitShamir · secp256k1
Compliance desk
Licence-replacement cases opened from conversion pre-flight.
Open cases
—| Case | Opened | Holder | Contact | Linked tx | Amount | Licence | Status |
|---|
Handling
IntakeConversion pre-flight
OwnerCompliance desk
SLA2 business hours
LicenceTraded-cash → tax-cleared
Penalty60% if converted first
RecordsSealed to audit chain
Each case is sealed into the hash-chained audit log when it opens, so contact intake
and licence replacement stay traceable end to end.
API
Console surface for the vault service.
GET /api/v1/health
GET /api/v1/state
POST /api/v1/login
POST /api/v1/logout
POST /api/v1/transactions
POST /api/v1/transactions/{id}/approve
POST /api/v1/transactions/{id}/sign
POST /api/v1/transactions/{id}/broadcast
POST /api/v1/transactions/{id}/cancel
GET /api/v1/report.csv
POST /api/v1/compliance/contact
POST /api/v1/compliance/license
POST /api/v1/compliance/tax-return
All write endpoints require the session CSRF token. Put this service behind TLS before it
leaves localhost.