SIGNING & CUSTODY SECURITY REVIEWS
Secure every step from key generation to recovery.
Review the signing stack, custody architecture, and operating procedures around MPC, HSM, multisig, wallets, approvals, recovery, break-glass access, and vendor dependencies.
Review surface
Follow authority from creation to recovery.
-
01 1. Generate Entropy, ceremonies, share or key creation, devices, participants, and evidence. -
02 2. Store & distribute HSMs, MPC shares, backups, physical controls, cloud dependencies, and separation. -
03 3. Request Transaction origination, policy inputs, destination controls, limits, screening, and integrity. -
04 4. Approve Identity, role separation, quorum, out-of-band checks, escalation, and exceptions. -
05 5. Sign & broadcast Signer behavior, transaction verification, tamper resistance, endpoint trust, and submission. -
06 6. Monitor & reconcile Alerts, logs, chain monitoring, settlement, reconciliation, and investigation. -
07 7. Recover & break glass Backup restoration, compromised devices, disaster recovery, emergency access, and post-event control.
Timing
Two engagement paths
Review an existing model
Challenge the architecture, implementation, procedures, and production controls around an operating stack.
Design or integrate a model
Support vendor selection, workflow design, role definition, integration, migration, and go-live readiness.
Walk critical scenarios
Examine compromise, insider abuse, vendor failure, data corruption, recovery, and break-glass paths.
Process
From key lifecycle mapping to go-live confidence.
- 01
Map the model
Document assets, participants, vendors, key and share locations, flows, roles, and assumptions.
- 02
Challenge controls
Test architecture, configuration, code or integration points, procedures, and human workflows.
- 03
Walk scenarios
Examine compromise, insider abuse, vendor failure, corruption, recovery, and break-glass paths.
- 04
Resolve and prepare
Prioritize changes, verify agreed remediation, and support the go-live or governance decision.
Outputs / What you receive
Clear findings, practical fixes, and a report your team can use.
Trust and failure model
Actors, assets, control boundaries, dependencies, and credible failure paths.
Prioritized control gaps
Technical and operational findings organized by impact and reachability.
Architecture and procedure guidance
Changes to design, integration, roles, approvals, recovery, or operations.
Decision-ready readout
Where required, a technical and executive view for launch, vendor, governance, or remediation decisions.
Typical engagement team
Who typically leads this work
The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Piotr Cielas
Principal Advisor
Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.
Currently
Head of Security, Agora
$45B+ in volume

Michal Bajor
Specialist Advisor
Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.

Timur Güvenkaya
Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
FAQ
Questions before scoping
Do you review MPC, HSM, and multisig models?
Yes. Scope covers the mechanism and the identity, devices, policy, quorum, integration, backups, recovery, monitoring, and procedures around it.
Can you review a third-party custody platform?
Yes. We can examine vendor assumptions, configuration, APIs, policy, transaction workflows, recovery, monitoring, and retained controls.
Is this a technical or operational review?
Usually both. Custody failures cross architecture, software, identity, process, people, vendor, and recovery boundaries.
Can you help before we choose a vendor?
Yes. The design path compares trust models, operating implications, control ownership, integration risk, and exit constraints.
Do you perform key ceremony exercises?
Key ceremony design, rehearsal, and readiness can be included or delivered through Training & Security Exercises.
Related services
Next step
Put the full signing path in view.
Share the architecture, vendors, wallet and transaction flows, target state, and the decision in front of you. We will identify the right review or design scope.
Discuss your scope