Solutions · Security
How secure is your custody, really?
A signing set is only as strong as its weakest habit: one device, one location, one person who is known to hold it. Sentinel scores where the arrangement has a single point of failure, checks the policy behind it, and gives you a document a security reviewer can work from.
- Single points of failure
- Backup geography
- Holder exposure
- Audit cadence
- Prepared for
- [Holder], private
- Prepared by
- [Advisor], BCGA Associate
- Arrangement
- 2-of-3, devices in three locations
- Verified
- Sample · September 2026
Verify it yourself
Don't take the brief's word for it.
The verdict on a policy is not an opinion. It comes from a proof engine that can be run on the same policy again and will say the same thing. Running it yourself is what the note below is holding a place for.
- 1The verdict is produced by a deterministic proof engine: the same policy gives the same result every time.
- 2Verifying a policy is a computation, not a call to a model or a service; the engine has no network dependency of its own.
- 3It contains no model, no temperature and no judgement call; nothing above it can overrule it.
What goes wrong
Three ways a sound setup is lost to a single failure.
One device is the whole arrangement.
A single hardware wallet is a single point of failure: lost, broken, or seized, it takes everything with it, and no backup on paper changes that.
Q1 · Current custody methodThe backup lives where the holder lives.
A fire, a flood or a search warrant reaches the device and its recovery material in one visit. Distance between them is the whole point of a backup.
Q6 · Backup & recovery material storageThe holder is known, and the recovery material is in one place.
A public profile turns a custody question into a personal-safety one. Recovery material held in one location makes the threat simple to act on.
Q7 · Holder identity exposure & physical recovery posture
What Sentinel checks for this
7 questions, weighted for security.
The same assessment serves every concern. For security, the audit question carries the most weight in the score, and the brief that follows is written around it.
The result is a governance score across five pillars and a written brief. It is not legal advice, and it does not replace the lawyer who will reference it.
- Q5Last security auditOperational · ×1
- Q1Current custody methodTechnical · ×1
- Q2Total asset value range (USD equivalent)Operational · ×1
- Q3Local regulatory postureCompliance · ×1
- Q4Succession plan in place?Policy · ×1
- Q6Backup & recovery material storageOperational · ×1
- Q7Holder identity exposure & physical recovery posturePhysical · ×1
Pillars and weights from the assessment template v1.1.0. The questions in bold are the ones this concern weighs first.
What Sentinel does not do
It never touches a device.
Sentinel is non-custodial by design. It reads a policy; it does not hold a key, sign a transaction, or see a seed. It scores the arrangement you describe, and the document it produces is yours to act on.
Begin with the assessment. Everything else follows from it.
Sample brief and verdict are synthetic and labelled as such. Questions from the assessment template v1.1.0. Custody Agents S.L., Barcelona.
Custody Agents S.L.