Network

Keys no one party can hold.

Distribute sensitive key material across independent operators, so one server, company or compromise cannot expose the whole key.

A transparent crystalline key
Threshold custodyIndependent operators hold shares, not complete keys.
Regular refreshShares rotate without reconstructing the key in one place.
Observable operationsRequests and disclosures can be logged and reviewed.

One request. Several independent shares.

The network is the cryptographic custody layer. Product policy still decides who may request an operation and under what conditions.

An approved system submits a requestThe application supplies the context
Request
Authority and conditions are checkedOnly an allowed request proceeds
Gate
Independent operators contribute sharesNo operator has the complete key
Threshold
One operation is completed and recordedThe result returns to the requesting system
Complete

Where distributed custody matters.

Use the network beneath systems where the cost of one compromised key is larger than the convenience of central custody.

Conditional disclosure

Recover one protected record when a public condition is met.

Keep encrypted identity data unreadable until an approved, pre-committed disclosure path is used.

Understand the architecture
Key infrastructure

Remove the complete key from every operator.

Protect signing and decryption workflows from a single point of custody failure.

View the operator network

Inspect the network before you depend on it.

See the operator surface, then use the documentation to understand where threshold custody fits your system.