Three independent institutions, in three jurisdictions. Every authorisation requires a two‑of‑three quorum.
Any two of the three must agree before anything moves, and one of the two is always Onramp MENA. No party can move a client’s Bitcoin alone, and no single failure can put it beyond reach. This page sets out how that holds, parameter by parameter.
& Primary Key Signer
Key split among separated custodians in Bahrain.
Key split within its own offline cold-wallet controls.
Recovery key split within its own controls. Non-custodial.
Every authorisation needs two of the three. One is always Onramp MENA.
The valid combinations are fixed in the architecture, not in a policy Onramp MENA can change.
Bitcoin only. Nothing else in scope.
- Asset
- Bitcoin (BTC) only
- Custody model
- Multi-Institution Custody, three-party 2-of-3 quorum
- Signature scheme
- On-chain multi-signature; no off-chain settlement layer
- Out of scope
- Brokerage | exchange services | custody of non-Bitcoin assets | yield arrangements
- Key segregation
- Independent key material per institution. No shared HSM.
- Operating jurisdiction
- Bahrain (intended CBB Cat-2 supervision)
- Counterparty jurisdictions
- Canada (Alberta provincial trust company); United Kingdom (insurance-backed recovery provider)
- Designed signing windows
- Onramp MENASame business day, within the operating hours of the requesting clientTetra TrustWithin 24 hours of video verification (baseline; a tighter expedited SLA is under negotiation)Coincover (once activated)Recovery on a reasonable-endeavours basis, within ~2 business days (aggregate)
- Recovery provider
- Recovery services via Coincover, an insurance-backed provider
- Recovery activation threshold
- 3 business days of documented unresponsiveness; attempts recorded via agreed secure channels
Each institution holds one key and does one job.
Onramp MENA
Mandatory signer on every authorisation. Validates each instruction against client policy and contributes the first signature, anchoring CBB supervisory accountability on every transaction.
Tetra Trust Company
Independent re-validation of every instruction under its own trust-company controls. Contributes the second signature in normal operations.
Coincover
Insurance-backed standby. Activates as second signer when Onramp MENA is non-responsive, after a three-business-day recovery threshold with documented attempts via agreed secure channels. In a signing-key-agent failure, also co-signs the client-directed recovery of assets to a replacement vault or the client’s own wallet.
What happens when a key partner is unavailable.
Tetra unavailable
Onramp MENA continues to hold the first signature; the second-signature path is paused until Tetra’s service is restored. Persistent unavailability is treated as a recovery event: under client direction, the client recovers their assets to a replacement vault or an address of their own, co-signed by the surviving Onramp MENA + Coincover quorum. Coincover does not substitute for Tetra in normal day-to-day operations.
Coincover unavailable
Onramp MENA + Tetra continue to sign normally. The recovery path is unavailable until Coincover service is restored, but normal operations are not affected.
Onramp MENA discontinuity
Tetra and Coincover hold sufficient signature material for the client to recover their assets, under client direction, to a replacement vault or an address of their own. See the recovery timeline below for the activation path.
- DAY 0 Non-responsiveness detected
- THROUGHOUT Documented attempts via agreed secure channels
- BUS. DAY 3 Recovery activation
Vault migration is another authorisation, never a back door.
Moving a vault follows the same quorum discipline as everything else. A client may elect to migrate at any time, authorised by the standard quorum (Onramp MENA + Tetra Trust). Where a key partner is permanently impaired, migration happens as a client-directed recovery: the client moves their assets to a replacement vault or an address of their own, co-signed by the surviving Onramp MENA + Coincover quorum, treated consistently with the other recovery scenarios rather than as ongoing operational co-signing. Either path enforces the no-privileged-exit principle on chain: there is no unilateral release path, and migration is treated as another authorisation.
The architecture is the audit. Verifiable on chain. Not assumed at the perimeter.