SIGNING & CUSTODY SECURITY REVIEWS

Secure every step from key generation to recovery.

Review the signing stack, custody architecture, and operating procedures around MPC, HSM, multisig, wallets, approvals, recovery, break-glass access, and vendor dependencies.

Review surface

Follow authority from creation to recovery.

A custody review path moving through policy gates and distributed signing nodes to a recovery check
  1. 01 1. Generate Entropy, ceremonies, share or key creation, devices, participants, and evidence.
  2. 02 2. Store & distribute HSMs, MPC shares, backups, physical controls, cloud dependencies, and separation.
  3. 03 3. Request Transaction origination, policy inputs, destination controls, limits, screening, and integrity.
  4. 04 4. Approve Identity, role separation, quorum, out-of-band checks, escalation, and exceptions.
  5. 05 5. Sign & broadcast Signer behavior, transaction verification, tamper resistance, endpoint trust, and submission.
  6. 06 6. Monitor & reconcile Alerts, logs, chain monitoring, settlement, reconciliation, and investigation.
  7. 07 7. Recover & break glass Backup restoration, compromised devices, disaster recovery, emergency access, and post-event control.

Timing

Two engagement paths

Review an existing model

Challenge the architecture, implementation, procedures, and production controls around an operating stack.

Design or integrate a model

Support vendor selection, workflow design, role definition, integration, migration, and go-live readiness.

Walk critical scenarios

Examine compromise, insider abuse, vendor failure, data corruption, recovery, and break-glass paths.

Process

From key lifecycle mapping to go-live confidence.

  1. 01

    Map the model

    Document assets, participants, vendors, key and share locations, flows, roles, and assumptions.

  2. 02

    Challenge controls

    Test architecture, configuration, code or integration points, procedures, and human workflows.

  3. 03

    Walk scenarios

    Examine compromise, insider abuse, vendor failure, corruption, recovery, and break-glass paths.

  4. 04

    Resolve and prepare

    Prioritize changes, verify agreed remediation, and support the go-live or governance decision.

Outputs / What you receive

Clear findings, practical fixes, and a report your team can use.

Trust and failure model

Actors, assets, control boundaries, dependencies, and credible failure paths.

Prioritized control gaps

Technical and operational findings organized by impact and reachability.

Architecture and procedure guidance

Changes to design, integration, roles, approvals, recovery, or operations.

Decision-ready readout

Where required, a technical and executive view for launch, vendor, governance, or remediation decisions.

Typical engagement team

Who typically leads this work

The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Currently

Head of Security, Agora

$45B+ in volume

Michal Bajor portrait

Michal Bajor

Specialist Advisor

Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Meet the full team

FAQ

Questions before scoping

Do you review MPC, HSM, and multisig models?

Yes. Scope covers the mechanism and the identity, devices, policy, quorum, integration, backups, recovery, monitoring, and procedures around it.

Can you review a third-party custody platform?

Yes. We can examine vendor assumptions, configuration, APIs, policy, transaction workflows, recovery, monitoring, and retained controls.

Is this a technical or operational review?

Usually both. Custody failures cross architecture, software, identity, process, people, vendor, and recovery boundaries.

Can you help before we choose a vendor?

Yes. The design path compares trust models, operating implications, control ownership, integration risk, and exit constraints.

Do you perform key ceremony exercises?

Key ceremony design, rehearsal, and readiness can be included or delivered through Training & Security Exercises.

Related services

Next step

Put the full signing path in view.

Share the architecture, vendors, wallet and transaction flows, target state, and the decision in front of you. We will identify the right review or design scope.

Discuss your scope