At The Lab logoContact

Wallet and custody systems

Wallet services, signing policy, HSM-backed key operations, and recovery controls assembled as one custody environment.

Custody scope

Define where keys live, who may use them, and how access is recovered.

Custody architecture starts with key ownership and approval policy, then connects applications to the appropriate software or hardware signing boundary.

Recovery, backup, operator roles, and audit evidence are designed with the signing workflow rather than added after deployment.

Wallet service

The wallet service receives an approved transaction request and applies network, account, and signing policy.

  • Account and network binding
  • Transaction validation and signing workflow
  • Receipt and status handling

Key custody

Key material can remain in protected software storage or inside the ATL PCIe HSM according to the assurance requirement.

  • Software and hardware-backed profiles
  • Application access through a limited operation API
  • Operator and service authorization policy

Recovery

Recovery is treated as a controlled process with separate material, custodians, and acceptance tests.

  • Encrypted wallet backup
  • Shamir-based recovery shares
  • Threshold, custodian, and restoration procedure

Audit and operation

The environment records key lifecycle and signing events needed for support, investigation, and policy review.

  • Key generation and activation records
  • Approved signing and administration events
  • Backup, restore, and continuity verification
Hardware custody option

Post-quantum key operations inside a PCIe HSM.

ATL post-quantum PCIe hardware security module
ATL PCIe HSMA hardware-backed key boundary for wallet and application services.
Project discussion

Define the requirement and deployment boundary.

ATL can scope this area as a focused component, an integration, or part of a complete engineering program.

Contact ATL