Testnet phase optitor runs on public testnets today. Mainnet follows an independent cryptography audit. Where we are

Company

Custody you can verify, run and leave.

optitor builds custody software for institutions that want to hold digital assets without trusting any single machine, person or vendor — including us.

Why optitor

The safest place for a key is nowhere in particular.

Custody failures tend to share a shape: one server, one administrator or one provider held enough power to move everything. optitor is designed so that none of them ever does.

The key behind every address is split across independent parties and never assembled. Every withdrawal needs a policy that your own quorum has signed. Every balance is checked against the chain. And the whole system runs on infrastructure you control, with a documented, tested way out.

Principles

What we will not compromise on.

  • 01

    Fail closed

    When something is missing — a policy, a price, a signature, a dependency — optitor refuses. An outage should cost you time, never funds.

  • 02

    Prove, do not assert

    Invariants are checked where they matter: the signer is recovered from every signature before broadcast, and the ledger is reconciled against the chain every five minutes.

  • 03

    No single point of trust

    No machine, person or vendor — including us — can move funds alone. Policy and cryptography are separate gates.

  • 04

    Yours to run

    You deploy optitor in your own cloud accounts, under your own deploy identities. Custody stays with the institution that is accountable for it.

  • 05

    Built to leave

    The recovery kit rebuilds a standard key that any standard wallet imports. Your assets never depend on optitor existing.

  • 06

    Say where we are

    We publish the gates still open before mainnet, and the residual risk the design does not remove. Trust should be earned in the open.

Where we are

Testnet today. Mainnet after an independent audit.

The custody platform — wallets, policy, approvals, ledger, reconciliation — is built and running on public testnets. Before mainnet, the MPC implementation goes through an independent cryptography audit, production signers move into attested Confidential VMs, and the recovery drill is completed.

See every open gate
  1. Now

    Custody platform live on public testnets

  2. Before mainnet

    Independent MPC audit, witnessed key ceremony, attested signers, restore drill, penetration test

  3. After the audit

    The mobile co-signer joins signing as an MPC party, not only as an approver

Contact

Talk to the people who built it.

See the security model working end to end.

Walk through a live testnet deployment with us: a policy publish approved on a phone, a withdrawal signed by two of three parties, and reconciliation against the chain.