Designed so trust is verified, never assumed.
Cermet's guarantees don't rest on “trust the operator.” They rest on cryptography you — and your device — can check.
3-of-3 MPC signing
The signing key is generated as three shares — one on your device, two in independent Cermet enclaves — and never assembled. Signing is a joint protocol; all three must cooperate, and no share can sign alone.
Hardware-isolated shares
Cermet's two shares run inside AWS Nitro and Intel SGX secure enclaves. Keys are used but never exported — the host OS, the network, and Cermet's own operators can't extract them.
Secure policy engine
Transfer and governance rules are evaluated inside the enclave before a signature is ever produced — a blocked action is never signed, not merely warned about.
Signed approvals
Each approval is a device signature over the exact bytes being authorized — non-repudiable evidence of who consented to what, not a server claim.
Tamper-evident ledger
Every action appends to a hash-chained log. Any edit, delete, or reorder breaks the chain — and your device re-verifies it, so a compromised server can't rewrite history unseen.
Break-the-glass recovery
You are never locked in. If Cermet is unavailable, an emergency path lets you reconstruct and move funds from your own encrypted backups — without Cermet's cooperation. A lost phone isn't a lost wallet.
Least-privilege access
Six roles gate every capability. Signers hold shares but don’t vote; approvers vote but hold no share; viewers read but can’t act; only the roles you choose can initiate or approve.
High-throughput, low-latency
Enclave-backed signing is built for production volume, so security scales with your treasury — you don't trade safety for the speed a real desk needs.
Read the deep-dive.
The verifiable activity ledger, the threat model, and how checkpoints keep even the operator honest.