StableOps
Get started
Security

Security by architecture.

Custody is split so no single region, cloud, or operator, including us, can ever move funds alone. Everything else, encryption, access, monitoring, recovery, is built around that guarantee.

  • MPC 2-of-3 signing across three regions on three clouds
  • Keys sealed in FIPS 140-2 Level 3 HSMs, never exported
  • SOC 2 Type II and ISO 27001, continuously monitored
Custody

No single point of compromise.

Every signing key is split into three shards held in three regions on three clouds. Any two can authorize; no one can act alone.

Region A · shard 1

Sealed in a FIPS 140-2 L3 HSM. Participates in signing, never reconstructs the full key.

Region B · shard 2

A different cloud and jurisdiction, so no provider or region is a single dependency.

Region C · shard 3

The third independent shard. Two-of-three signs; a lost region never loses the funds.

Controls

Defense in depth.

The guarantees that surround custody, from the network edge to the audit log.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, with keys managed in dedicated HSMs.

Least-privilege access

SSO, hardware keys, and just-in-time, fully logged access to production.

Monitoring & anomaly detection

24/7 detection on policy, behavior, and on-chain activity, with on-call response.

Recovery, rehearsed

Pre-registered guardians and time-locks. Procedures rehearsed quarterly.

Screening built in

Every address and transfer screened against sanctions and risk lists.

Signed audit log

Every action stamps a tamper-evident, exportable ledger entry.

Responsible disclosure

Found something? We run a coordinated disclosure program and reward valid reports. Encrypt sensitive details with our PGP key and we will acknowledge within one business day.

security@stableops.finance

Ready to get started? Provision a wallet, talk to an engineer, or pick a plan and ship.

Have more questions?
Talk to a solutions engineer, or read the docs.