Sovereign Custody

Rox Vault

Zero Vendor Trust MPC custody, with Self-Custody Nodes deployed inside your own cloud or on-prem infrastructure. You control every key shard. No vendor co-signing, ever.

Zero

Key shards held, seen or processed by the vendor

None

Vendor signing paths: no shards, no partials, no aggregation

2

Independent layers: governance approval and threshold signing

8

Major regulatory bodies mapped in the compliance framework

Custody where the vendor cannot touch your keys

Rox Vault is institutional digital-asset custody built on a Zero Vendor Trust architecture. It uses MPC, multi-party computation, which splits a private key into encrypted shards so the full key never exists in one place. The difference is where signing runs: only on Self-Custody Nodes your institution deploys and controls.

Rox never holds a key shard and has no computational path to execute a transaction, so even a full compromise of vendor infrastructure adds no signing capability. Governance approval and threshold signing live in independent boundaries, making every approval and its signature the same auditable event.

Two named layers make this concrete: a Governance Enforcement Layer that turns institutional policy into deterministic approvals, and a Distributed Institutional MPC Layer, the network of your own nodes, that performs the cryptography. On that foundation sit wallet-as-a-service, stablecoin infrastructure, treasury management and multi-vault operations, connected to issuance, trading and settlement on the same sovereign stack.

How Rox Vault flows

01

Deploy your Self-Custody Nodes

Your institution deploys the only nodes that will ever hold key material.

02

Generate keys that never exist whole

Distributed key generation means no one ever sees a complete private key.

03

Governance approves the transaction

The policy engine checks every rule before a transaction is approved.

04

Your nodes sign and broadcast

Your nodes assemble the signature, broadcast, and log every step.

THE FRICTION IT REMOVES

The problems it solves

Vendor signing power

01

In traditional MPC and HSM custody, the vendor acts as a co-signer or holds key material in its own infrastructure. If that vendor is compromised, coerced or simply unavailable, the institution's assets are at risk. Rox Vault eliminates this dependency by design: the vendor has no shards and no signing role.

Regulators judge capability, not intent

02

A vendor's promise not to use its signing ability is irrelevant to supervisors; the ability itself is what gets classified. Systems where the vendor could theoretically sign are treated as higher-risk custody or outsourcing arrangements. Rox Vault is built so that no signing capability exists to classify.

Governance and cryptography in one trust boundary

03

When approval policies and signing run inside the same vendor-controlled system, there is no deterministic link between a human decision and the signature it produces. Rox Vault splits them across independent boundaries, one for intent, one for execution, so the approval and the signature become the same auditable event.

Compliance that fragments across jurisdictions

04

Each regulator imposes distinct technical and operational requirements, and a design built for one framework often fails another. Rox Vault's framework provides jurisdiction-specific compliance mapping across eight major regulatory bodies, so institutions can operate across markets without rebuilding their compliance infrastructure.

UNDER THE HOOD

Inside Rox Vault

A closer look at what each part of Rox Vault does for you.

Zero Vendor Trust architecture

The vendor is structurally removed from the signing path, not just contractually restrained.

  • No key shards, partial signatures or aggregation ever inside vendor infrastructure
  • Compromise of vendor systems adds no signing capability under the defined threat model
  • Institutions retain full authority over transaction authorization and execution

Governance and policy enforcement

A deterministic approval engine that binds human decision-making to transaction execution, enforcing every institutional rule as a hard constraint before signing is activated.

  • Role-based authorization with maker-checker workflows and segregation of duties
  • Multi-factor authentication and device binding on every approval, with immutable audit logs of every governance action
  • Static and dynamic policies: approver roles, thresholds, transaction categories, amount-based rules, counterparty logic, time windows and risk-flag escalation

Distributed Institutional MPC Layer

Threshold signing executed exclusively across Self-Custody Nodes the institution deploys and controls.

  • Distributed key generation: wallets created without any single party seeing the key
  • Encrypted key shards held locally on each node, with encrypted backups
  • Peer-to-peer exchange of partial signatures, never routed through the vendor

Built for regulatory examination

Compliance is a structural property of the architecture, not a report generated after the fact.

  • Jurisdiction-specific compliance mapping across eight major regulatory bodies
  • Key management separated from transaction authorization to support segregation-of-duties requirements
  • Complete, tamper-evident audit trails with independent auditor access for examination readiness

How Rox Vault works

01

Deploy your Self-Custody Nodes

Your institution stands up a network of Self-Custody Nodes under its own control, on premises, in a private cloud, or spread across multiple clouds for resilience. These nodes, and only these nodes, will ever hold key material.

02

Generate keys that never exist whole

The nodes run distributed key generation, creating wallets collaboratively so that no single machine, person or vendor ever sees a complete private key. Each node holds only its own encrypted shard, backed up under your control.

03

Governance approves the transaction

An authorised approver authenticates with multi-factor authentication and device binding, and the policy engine evaluates the request against your rules: roles, thresholds, whitelists, limits and maker-checker workflows. Only when every condition is satisfied does the transaction receive an approval flag.

04

Your nodes sign and broadcast

On approval, the nodes exchange partial signatures peer to peer and a deterministic leader assembles the final signature, with no partial signature or key material ever leaving your nodes or traversing Rox infrastructure. The signed transaction is then broadcast to the network, and every step from approval to execution is written to an immutable audit log, so the approval and the signature are the same auditable event.

Beyond the point solutions

Custody-only vendors stop at key management, and most retain signing capability in their own infrastructure. Rox Vault removes the vendor from the trust boundary entirely, then connects custody to issuance, trading, settlement, banking, and payments on the same sovereign stack.

They stop here. Rox continues.

Request a Technical Briefing

See Rox Vault in action.