Security & compliance

Crypto custody security you can verify, not just trust.

Nodus360 custody runs on io.finnet’s trustless MPC — an M-of-N implementation independently audited by Kudelski Security, with open-source cryptography and open-source recovery. Here is exactly what protects your digital assets, layer by layer, so your CISO can review it instead of taking our word for it.

Cryptography

Trustless MPC

Weighted signing authority distributed across unlimited parties. A valid signature is computed without the private key ever existing in one place.

Key material

Nobody else holds a share

Neither Nodus360 nor io.finnet holds key material. There is no provider-held key and no backend dependency for signing.

Devices

Secure Enclave & biometrics

Signer shares are protected in device hardware; approvals require biometric authentication in the mobile app.

Automation

Policy-bound Virtual Signer

Server-side signing runs inside a trusted execution environment and can only act within the policy you defined.

Controls

Policy engine & audit trail

Allow-lists, limits and approval rules per vault, with verifiable logs of every request, approval and signature.

Continuity

Recovery without us

BIP39 disaster recovery with an open-source, offline tool. Your access does not depend on our availability.

Assurance

Audited cryptography, published openly

The M-of-N trustless MPC implementation behind every Nodus360 vault has been independently audited by Kudelski Security, and the cryptography is open source — reviewable by your own security team or an auditor of your choosing.

Ask us for the technical white paper and the current certification status of the underlying platform. We would rather send you the evidence than a trust badge.

M-of-N trustless MPC
Independent cryptographic audit
Audited — Kudelski
Open-source cryptography
Reviewable by your own team
Public
Technical white paper
Architecture and threat model
On request
Platform certifications
Held at infrastructure level — current status on request
Ask us

Send this page to your CISO. Then send us their questions.

We will walk your security and compliance teams through the architecture, the audit and the recovery procedure in as much detail as they want.

Request access