Built so the worst day isn't catastrophic.

Layered controls, separation of duties, on-chain auditability. If a key is compromised, the blast radius is small.

Three security personas — laptop operator, thinker, and walkie-talkie agent — sharing a thought cloud of locks, 2FA, shield, fingerprint, key, audit list, firewall, watchful eye and safe

Posture

Multi-signature by default: Hot, cold, and payment wallets all require multiple signers. Single-key wallets are opt-in only.
Velocity controls: Cap how much can move in a window. Limits are enforced on-chain, not in the UI.
Role-based access: Initiators ≠ approvers ≠ admins. Required separation of duties at every tier above Free.
AirGap key ceremonies: Cold-storage keys never touch a connected machine. Industrial-grade data transfer.
Audit log, exportable: Every action timestamped & attributed. SOC-ready export your auditor will accept.
Encryption at rest & in flight: TLS 1.3 in transit, AES-256 at rest, customer-managed keys at the Business tier.

Every transaction settles on-chain.

There's no internal ledger pretending to be your balance. Every movement is a real, trackable blockchain transaction — so audits are simple, the accounting madness goes away, and rehypothecation risk is simply gone. What you see on-chain is what you have.

Certifications & reports

SOC 2 Type II
In progress
Q3 2026
ISO 27001
In progress
Q4 2026
Penetration test
Annual
Latest: Jan 2026 · report on request

Responsible disclosure

Found something? Email security@guveno.com with a PoC and we'll respond within one business day. Critical findings are bounty-eligible.

-----BEGIN PGP PUBLIC KEY-----
[ PGP key fingerprint ]
[ … ]
-----END PGP PUBLIC KEY-----