Choose your signing path
Use WalletSuite MPC, self-hosted OWS, external signers, signed-payload workflows, or customer-controlled HSM/KMS behind one governance layer.
One governance layer for policy, approvals, signing, automation controls, and audit evidence — across WalletSuite MPC, self-hosted OWS, external signers, and customer-controlled HSM/KMS.
Last updated: May 2026
Treasury, payment ops, and compliance teams standardize policy, approvals, signing, and audit evidence — without rip-and-replace.
Use WalletSuite MPC, self-hosted OWS, external signers, signed-payload workflows, or customer-controlled HSM/KMS behind one governance layer.
Turn internal wallet rules into tenant-scoped policies, approval flows, admin controls, and customer-visible evidence.
Attach policy version, decision reason, approval trail, signer path, and verifiable audit evidence to every transaction.
Run WalletSuite in shadow mode alongside existing backend rules before turning on enforcement. No big-bang migration.
Separate read, prepare, approve, sign, and broadcast so agents and backend jobs operate inside explicit mandates.
Bands are the explicit phases of a wallet operation. Agents and backend jobs only get the bands their mandate allows.
Balances, allowances, prior decisions, and policy context. Read-only by default for agents.
Compose unsigned transactions. Policy evaluates the action before it reaches a signer.
Route approvals to the right humans or systems, then sign through WalletSuite MPC, OWS, or the selected signer path.
Submit to chain, write audit evidence, and reconcile status back to the source system.
Use WalletSuite as the governance layer across the signing model that fits your workflow — no rip-and-replace.