The questions custody teams ask first.
Self-custody with shared control. Every signature is 3-of-3: you hold one share on your device and Cermet holds two inside secure enclaves. Cermet can never sign without you — and a break-the-glass path means you can recover your funds even if Cermet disappears entirely. No single party, Cermet included, can move your funds alone.
You're never locked in. Cermet's shares live in hardware enclaves, but the design includes a break-the-glass recovery path: using your own encrypted backups, you can reconstruct and move your funds without Cermet's cooperation. Shared control never becomes hostage-taking.
Nothing is lost. Your share is one of several; the wallet re-keys the remaining shares to a new device through your quorum, and an encrypted backup can restore your share — a stolen backup can’t spend without your password and the quorum.
No. Keys are generated with MPC and never exist whole, so there’s no single secret to lose, phish, or leak. Recovery is governed by your quorum and encrypted backups instead.
40+ networks — Ethereum and EVM chains, Bitcoin, and Solana — from one wallet, with the right signing curve chosen per chain. One address to fund and manage across all of them.
Access is least-privilege across six roles — owner, admin, editor, signer, approver, viewer. Some hold a share and sign, some only vote, some are read-only, and removal is restricted by role. Roles.
Rules are evaluated by the coordinator before any signature is produced. A blocked or unapproved transfer never gets signed — enforcement happens at signing time, not as an after-the-fact warning.
Yes. Actions append to a hash-chained ledger, and your device re-verifies the chain plus the signatures on each entry. A rewritten history breaks the chain — the check fails on your side, not just ours.