Keys split, never assembled
Your signing key is generated as three independent shards held on separate hardware in separate jurisdictions. A transaction needs any two — the full key never exists in one place, not even for a millisecond.
Keel is the settlement and custody layer for on-chain treasuries. MPC key architecture, hardware-backed signing, and a programmable policy engine — so your assets stay self-custodied and provably yours.
No single point of failure, no custodial black box. Every signature is policy-checked and every reserve is provable on-chain.
Your signing key is generated as three independent shards held on separate hardware in separate jurisdictions. A transaction needs any two — the full key never exists in one place, not even for a millisecond.
Shards live inside FIPS 140-2 Level 3 secure enclaves and certified HSMs. Keys are non-exportable by design — they can sign, but they can never leave the silicon.
Every vault publishes a Merkle-attested balance to a public contract each epoch. Anyone can verify that assets on record match assets on-chain — no quarterly PDF required.
Spending limits, address allowlists, time locks, and multi-approver quorums — enforced at the protocol layer, before anything is signed.
Eleven independent audits from Cerberus Labs, Ostrom Security, and Veric Research, plus $250M of custody insurance underwritten by Lloyd’s.
Keel is non-custodial by construction. We operate the infrastructure; you retain a shard and full withdrawal authority. If Keel disappears, your assets do not.
A member proposes a transfer from the dashboard or API. It enters the queue unsigned — no keys have touched it yet.
Limits, allowlists, and quorum rules run first. A transfer outside policy is rejected before any shard is asked to sign.
Two independent shards each produce a partial signature inside their enclave. Neither ever sees the other’s material.
The signature is assembled, broadcast, and the vault’s new reserve balance is attested on-chain in the same epoch.
Native support across mainnets and L2s, with unified policy and reporting. Add a network in a click — no new keys, no new integrations.
Open a vault in minutes with a guided setup, or talk to our custody engineers about a bespoke policy and quorum design.