Security model

Designed so trust is verified, never assumed.

Cermet's guarantees don't rest on “trust the operator.” They rest on cryptography you — and your device — can check.

01

3-of-3 MPC signing

The signing key is generated as three shares — one on your device, two in independent Cermet enclaves — and never assembled. Signing is a joint protocol; all three must cooperate, and no share can sign alone.

02

Hardware-isolated shares

Cermet's two shares run inside AWS Nitro and Intel SGX secure enclaves. Keys are used but never exported — the host OS, the network, and Cermet's own operators can't extract them.

03

Secure policy engine

Transfer and governance rules are evaluated inside the enclave before a signature is ever produced — a blocked action is never signed, not merely warned about.

04

Signed approvals

Each approval is a device signature over the exact bytes being authorized — non-repudiable evidence of who consented to what, not a server claim.

05

Tamper-evident ledger

Every action appends to a hash-chained log. Any edit, delete, or reorder breaks the chain — and your device re-verifies it, so a compromised server can't rewrite history unseen.

06

Break-the-glass recovery

You are never locked in. If Cermet is unavailable, an emergency path lets you reconstruct and move funds from your own encrypted backups — without Cermet's cooperation. A lost phone isn't a lost wallet.

07

Least-privilege access

Six roles gate every capability. Signers hold shares but don’t vote; approvers vote but hold no share; viewers read but can’t act; only the roles you choose can initiate or approve.

08

High-throughput, low-latency

Enclave-backed signing is built for production volume, so security scales with your treasury — you don't trade safety for the speed a real desk needs.

Read the deep-dive.

The verifiable activity ledger, the threat model, and how checkpoints keep even the operator honest.