Trust

What SigVault can and cannot do

Custody products ask you to trust them. We'd rather you check. This page states exactly what our software can do, what it cannot do, what we can see, and what happens to your bitcoin if we're compromised, coerced, acquired, or gone.

Last updated 10 August 2026. If anything here is wrong or out of date, email security@sigvault.org and we'll fix it publicly.

01 · Signing

Where signing happens

Private keys are generated on your hardware wallet and never leave it. Signing happens on the device, and the transaction is displayed on the device's own screen for you to verify — not just in our interface.

This matters more than it sounds. In February 2025, Bybit lost $1.46 billion because the signing interface showed approvers a transaction different from the one they were signing. The multisig was correct. The screen lied. Verify on your device, never in a browser — with us or with anyone else.

02 · Visibility

What our servers can see

Private keys, seeds, key materialnever
Extended public keys and output descriptorsvisible
Wallet balances and transaction historyvisible
Partially signed transactions (PSBTs)visible
Vault policy — quorum, signers, timelocksvisible
Signing ceremony state and participantsvisible
Your account identity and organization membershipvisible
Encrypted wallet state in object storagestored encrypted

We are not private by default with respect to balances. If your threat model requires that nobody knows what you hold, run your own wallet service (below) or use a local wallet like Sparrow.

03 · Control

Can SigVault move your money?

No.

Producing a valid transaction requires signatures from your hardware wallets, meeting the threshold in your vault policy. We hold none of those keys — unless you explicitly added a SigVault-held key to your quorum, in which case we hold exactly one, it is labelled as ours everywhere it appears, and it cannot reach any threshold above one on its own.

Set your quorum so that our key is never decisive. If you're running 2-of-3 with one SigVault key, we plus one compromised signer could move funds. That's a real consideration and you should design around it. We'd rather say so.

04 · Blast radius

What an attacker who fully compromised our servers could do

Honestly:

could
  • See all balances, transaction history, and vault policies
  • Attempt to show you a fraudulent transaction and hope you approve it without checking your device screen — this is the Bybit attack, and verifying on-device defeats it
  • Deny service: stop ceremonies, block coordination, take the product offline
  • Attempt to substitute a receive address — always verify receive addresses on your hardware wallet
could not
  • Produce a valid signature for your vault
  • Reconstruct your keys
  • Prevent you from recovering funds independently
05 · Recovery

Recovering without us

Every SigVault vault is a standard output descriptor built on BIP-388 and Miniscript. Export it — you can do this at any time, from any plan, including free — and recover your funds in Sparrow or any descriptor-capable wallet. You need your descriptor and the required number of hardware wallets. You do not need our cooperation, our servers, or our continued existence.

Time-locked recovery paths are enforced by the Bitcoin network, not by us. They execute on schedule whether this company exists or not.

Export your descriptor today and store it with your backups. Do this before you need it.

06 · Self-hosting

Running it yourself

You can pair your own instance of walletrs, our wallet service, and bind your vaults and signing devices to it. Traffic for those vaults is routed to your instance, on your infrastructure, behind an IP allow-list you control. Binding is immutable — a vault is created against one instance and stays there.

Most customers won't do this. The ones who do keep the architecture honest for everyone else.

How to run your own wallet service
07 · Source

What's open, and what isn't

Desktop signer (sigvault-desktop)Open source, BSD-3-Clause
Wallet service (walletrs)Being split into a standalone repo under dual MIT / Apache-2.0. Phase 0 merged.
Coordination APIClosed
Web dashboardClosed

We think closed cryptographic code is a fair reason to distrust a custody product, which is why walletrs is being opened. Until it is, this row of the table is an honest liability rather than a footnote.

08 · Audit

Independent review

No third-party security audit has been completed.

One is being scoped; when it lands we will publish the full report — findings included, not a summary — along with a table mapping each finding to the commit that fixed it.

Until then, what we can offer is this page, the open-source signer, and the fact that your funds are recoverable without us.

We have not had a security incident. We have also not yet had enough users or enough time for that to mean very much, and we'd rather say so than imply a track record we haven't earned.

09 · Disclosure

Reporting a vulnerability

security@sigvault.org. Please report privately rather than opening a public issue. We'll acknowledge within 72 hours, and we'll credit you publicly unless you'd rather we didn't. A funded bounty program is planned but does not exist yet — we won't pretend otherwise.

10 · Limits

What we don't protect against

A compromised computer

If your machine is compromised, an attacker can show you a false transaction. Verify on your hardware wallet's screen.

Losing your keys

If you lose enough devices and backups to fall below your threshold, and no recovery path is configured, the funds are gone. We cannot help. Configure a recovery path.

Coercion

A quorum spread across people and places raises the cost of a physical attack considerably, but nothing here makes you immune. Consider geographic distribution, timelocks, and not talking publicly about what you hold.

Bad policy design

A 2-of-3 where one person holds two keys is a 1-of-1 wearing a costume. We'll help you avoid this; ultimately the policy is yours.

Bitcoin itself

Consensus bugs, chain reorganizations, fee-market conditions. Nobody protects against these.

Still here? Then you're the kind of person
we built this for.

Create a free vault on signet and run a ceremony against everything on this page.

Back to sigvault