Platform
One custody system, from key to ledger.
optitor covers the whole life of a digital asset in custody — key generation, deposit addresses, policy, approvals, signing, gas, settlement and reconciliation — with one data model, one audit trail and no step that trusts a single machine.
MPC wallets
Wallets backed by a key that never exists in one place.
Each vault account is controlled by its own distributed key. Three parties generate it together, each keeps only its own share, and only the public key ever leaves a node.
- Threshold ECDSA (CGGMP21) over secp256k1 — 2-of-3 by default, configurable per deployment.
- Distributed key generation. The coordinator sees public keys only and relays messages it cannot read.
- Fast signing. Presignatures keep the online part of a signature to about one round.
- Weekly proactive refresh. Every share is re-randomized; the public key and every address stay the same.
- Identifiable abort. A misbehaving party is named by the protocol, not guessed at.
- Unlimited deposit addresses. Derived from the public key alone — instant, with no ceremony per address.
Policy engine
A policy engine that fails closed.
Transaction Authorization Policy rules decide which requests may ever reach the signers — and the active policy is signed by your admin quorum, so editing it in the database achieves nothing.
- Match on what matters: operation, asset, chain, source vault, destination type and amount — per transaction or as a rolling velocity limit, in USD or native units.
- Three outcomes: allow, block, or require approval from AND/OR combinations of approver groups with their own thresholds.
- Default deny. First match wins; no match, no active policy or a stale price means blocked.
- Draft, simulate, publish. Dry-run a request against a draft; publishing needs your admin quorum, each member signing with a device key.
- Verified at the signer. Every signing node checks the quorum signatures and refuses an older policy version.
- 10
Small, whitelisted
Require Ops ×1 - 15
Daily velocity cap
Require Ops ×2 + Security ×1 - 20
Large, whitelisted
Require Ops ×2 + Security ×1 - 30
One-time address
Require Ops ×2 + Admin ×1 - 999
Default deny
Block
first match wins no rule or no active policy ⇒ blocked Illustrative rules
Approvals
Approvals with passkeys and secure hardware — never passwords.
People approve with credentials that cannot be phished or replayed: passkeys bound to your console's address, and device keys that never leave a phone's secure hardware.
- Passkeys-only console. Face ID, Touch ID, Windows Hello or a security key — there is no password to steal.
- Step-up bound to the action. High-value creates and approvals need a fresh check tied to that transaction and amount.
- Deny wins. One eligible rejection ends a request, and every request expires.
- Quorum for privileged changes — publishing policy, approving a whitelist entry, re-arming a frozen asset, switching networks.
- Phone approvals that verify themselves. The co-signer app recomputes what it signs and refuses a mismatch.
Address whitelisting
New destinations wait. Approved ones are pinned.
Internal wallets, counterparties and contracts share one lifecycle: added as pending, approved by your quorum, and spendable only after a cooldown.
- Checksum-validated addresses only (EIP-55), per chain and asset.
- Two independent gates. Quorum approval and the cooldown must both pass.
- One-time addresses can be switched off for the whole workspace.
- Disable instantly. A disabled entry refuses new withdrawals at once.
- Added Pending · EIP-55 checked
- Quorum approval Admin quorum + step-up
- Cooldown 24–48 h before it can receive
- Active Spendable destination
A withdrawal to this address now fails with DESTINATION_IN_COOLDOWN.
Gas Station
Gas that funds itself — inside the same controls.
Before a token withdrawal, optitor checks that the source address holds enough native gas. If it does not, a top-up comes from a gas treasury that is itself an MPC vault.
- Automatic treasury. The gas vault is created for you and funds every enabled chain from one address.
- Same pipeline as everything else. Top-ups are signed, broadcast and ledgered like any transaction.
- Scoped by policy. A dedicated rule limits top-ups to your own custody addresses, with a per-address daily cap.
- Never overpays. A gas-price ceiling pauses top-ups in fee spikes; a low treasury raises an alert.
- Ready native ≥ minimum Withdrawal proceeds
- Topping up below minimum · price ≤ cap Treasury sends a capped top-up, then retries
- Blocked below minimum · price > cap Backs off — never overpays
Gas treasury · MPC vault
0x2c4f…b71e
One funding address on every enabled chain · per-address daily cap · alert when low
Deposits & withdrawals
Credited on finality. Broadcast exactly once.
The deposit pipeline and the withdrawal outbox are engineered for the failure cases — reorgs, crashes, stuck transactions and tokens nobody vetted.
Deposits
- A persisted scan cursor per chain, so downtime never skips a block.
- Credited after confirmations or the finalized tag, with a reorg guard on the block hash.
- Unknown tokens are quarantined — never credited, always alerted.
- Native coins are gas only; a stray native deposit raises an alert instead of a credit.
- Every credit is a double-entry posting, with token decimals pinned in the registry, never read on-chain.
Withdrawals
- A durable outbox with a per-address nonce allocator — never a fire-and-forget background task.
- Persist, then broadcast. The signed transaction is stored first; a retry resends the same bytes.
- Signature checked against the custody address before anything reaches the network.
- Finalized on receipt, not on broadcast. Stuck transactions can be sped up or canceled at the same nonce.
- One funded source. Consolidation sweeps keep the vault's root address ready; excess hot balance goes to a pre-approved cold address.
Reconciliation & controls
Your ledger and the chain agree — or withdrawals stop.
Every five minutes optitor sums on-chain balances across every custody address and compares them with the double-entry ledger, per chain and token.
- Drift freezes withdrawals for that chain and token; deposits keep crediting.
- Re-arming takes a quorum — resolving the alert alone never unfreezes anything.
- A kill switch halts every outbound movement at once; lifting it needs the quorum.
- Per-vault freezes, plus outflow circuit breakers that pause automatically and re-arm only by hand.
-
Base USDC
In balanceon-chain 1,204,880.00 ledger 1,204,880.00
-
Polygon PoS USDC
In balanceon-chain 318,402.55 ledger 318,402.55
-
Arbitrum One USDT
In balanceon-chain 96,000.00 ledger 96,000.00
-
Optimism USDC
Drift · frozenon-chain 41,250.00 ledger 41,260.00
Withdrawals of USDC on Optimism stop until an admin quorum re-arms them — deposits keep crediting. Illustrative balances
Chains & tokens
Every EVM chain, one switch, no new keys.
A deployment runs on testnet or mainnet. Every cataloged chain of that network is live, and because addresses come from the vault key, a new chain needs no new key and no new address.
- 118 EVM chains cataloged — 79 mainnet and 39 testnet — each with pinned RPC defaults you can replace.
- Add an uncatalogued chain by hand; it needs your admin quorum and a step-up.
- Vetted tokens only. 50 well-known tokens are active where the catalog pins a contract; anything else is quarantined.
- Primary and fallback RPC per chain, with finality and reorg guards on everything that credits funds.
Testnet
39 chains
USDC and LINK where contracts are pinned
Mainnet
79 chains
216 chain–token pairs across 50 well-known tokens
Switching is one change for the whole workspace: it needs your admin quorum and a step-up, takes effect live, and moves no balances.
Audit & observability
An audit trail even a database admin cannot rewrite.
Every change writes an audit record. Audit logs and ledger entries are append-only by database grant and trigger, and exported every night to immutable storage.
- Hash-chained daily manifests. A rewritten history breaks the chain and stops the export.
- Long retention on immutable blob storage — seven years or more.
- CSV export of transactions, deposits, top-ups and analytics, filtered and sorted server-side.
- Metrics and alerts for deposit lag, pending withdrawals, reconciliation drift, gas and signer health.
- Signed webhooks for every event, with delivery logs and replay.
Immutable storage · ≥ 7 years Rewrite one row and the next export's chain check fails — and the export halts.
Illustrative hashesSee the platform on a live testnet deployment.
We will walk your team through a deposit, a policy-gated withdrawal signed by two of three parties, and the reconciliation that checks it — on infrastructure you could run yourself.