Security Model

Advanced MPC Threshold Security Module (TSM)

Institutional Vault uses Blockdaemon's Advanced MPC Threshold Security Module (TSM), a wallet security platform designed to combine robust private key protection with operational accessibility.

The off-chain nature of Multi-Party Computation (MPC) enables multi-party approval enforcement (which previously often required on-chain multisig) in a more flexible and chain-compatible way.

Key properties

For how key shares are protected in confidential computing environments (AWS Nitro Enclaves, Azure Confidential Containers, KMS attestation, and defense in depth versus physical HSMs), see MPC and TEE Security Architecture.


Institutional Vault Policy Engine

Institutional Vault’s policy engine is implemented inside the MPC Policy Authority (MPA): a cluster of 3 independent policy nodes that each evaluate policy before any operation is executed. This design delivers stronger guarantees than a traditional “policy service” because policy enforcement is cryptographically enforced and quorum-based, not merely an application-layer check.

MPC Policy Authority

Policy Node #3

Policy Engine 3
MPC Protected Policy Layer
Cryptographically enforced rules

Key Share #3
Partial key fragment

Policy Node #1

Policy Engine 1
MPC Protected Policy Layer
Cryptographically enforced rules

Key Share #1
Partial key fragment

Policy Node #2

Policy Engine 2
MPC Protected Policy Layer
Cryptographically enforced rules

Key Share #2
Partial key fragment

Key properties

What the policy engine can do (capabilities)

🗣️We Are Here to Help!

Please contact us via email or support chat if you encounter an issue, bug, or need assistance. Don't forget to include any relevant details about the problem. To request a wallet form and Institutional Vault Approver form, please click here or contact our sales team.

Updated 2 months ago