Skip to main content
Custody architecture

Three independent institutions, in three jurisdictions. Every authorisation requires a two‑of‑three quorum.

Any two of the three must agree before anything moves, and one of the two is always Onramp MENA. No party can move a client’s Bitcoin alone, and no single failure can put it beyond reach. This page sets out how that holds, parameter by parameter.

Across institutionsThe quorum

Onramp MENA
Transaction Coordinator
& Primary Key Signer
Bahrain
Tetra Trust
Signing Key Agent
Canada
Coincover
Recovery Key Agent
United Kingdom
2 of 3
Any two of the three must agree before anything moves
Within each institutionNo single person holds a complete key

Onramp MENA

Key split among separated custodians in Bahrain.

12345
3 of 5 to reconstruct
Tetra Trust

Key split within its own offline cold-wallet controls.

12345
3 of 5 to reconstruct
Coincover

Recovery key split within its own controls. Non-custodial.

12345
3 of 5 to reconstruct
For illustrative purposes. The key agents’ schemes stay confidential by design. Publishing them would weaken the security they provide.
Signing workflowOffline · air-gapped

01
Initiate
Withdrawal request via the Onramp MENA platform
02
Verify
Checked against the client’s authorisation policy
03
Sign first
Onramp MENA reconstructs its key and signs
04
Co-sign
One agent adds the second signature | 2-of-3 met
05
Broadcast
The signed transaction is sent to the Bitcoin network
Signing takes place offline, in air-gapped environments. Private keys never touch the internet.
Two levels of quorum: multiple people within each institution, multiple institutions for every transaction. Collusion would require compromising multiple individuals across multiple independent organisations at once. And should any one institution fail, the other two can still recover the client’s assets.
Architecture in design | not yet operational
The rule

Every authorisation needs two of the three. One is always Onramp MENA.

The valid combinations are fixed in the architecture, not in a policy Onramp MENA can change.

Normal operations
Onramp MENA + Tetra Trust
Recovery scenarios
Onramp MENA + Coincover
Only when Onramp MENA is unresponsive for three business days
Tetra Trust + Coincover
Specification

Bitcoin only. Nothing else in scope.

Designed parameters
Scope
Asset
Bitcoin (BTC) only
Custody model
Multi-Institution Custody, three-party 2-of-3 quorum
Signature scheme
On-chain multi-signature; no off-chain settlement layer
Out of scope
Brokerage | exchange services | custody of non-Bitcoin assets | yield arrangements
Key segregation & jurisdictions
Key segregation
Independent key material per institution. No shared HSM.
Operating jurisdiction
Bahrain (intended CBB Cat-2 supervision)
Counterparty jurisdictions
Canada (Alberta provincial trust company); United Kingdom (insurance-backed recovery provider)
Timing & recovery
Designed signing windows
Onramp MENA
Same business day, within the operating hours of the requesting client
Tetra Trust
Within 24 hours of video verification (baseline; a tighter expedited SLA is under negotiation)
Coincover (once activated)
Recovery on a reasonable-endeavours basis, within ~2 business days (aggregate)
Recovery provider
Recovery services via Coincover, an insurance-backed provider
Recovery activation threshold
3 business days of documented unresponsiveness; attempts recorded via agreed secure channels
Architecture in design | not yet operational
The three roles

Each institution holds one key and does one job.

Primary key signer

Onramp MENA

Manama, Bahrain | CBB Cat-2 (application in preparation)

Mandatory signer on every authorisation. Validates each instruction against client policy and contributes the first signature, anchoring CBB supervisory accountability on every transaction.

Signing key agent

Tetra Trust Company

Calgary, Canada | Regulated trust company

Independent re-validation of every instruction under its own trust-company controls. Contributes the second signature in normal operations.

Recovery key agent

Coincover

Cardiff, United Kingdom | Insurance-backed recovery provider

Insurance-backed standby. Activates as second signer when Onramp MENA is non-responsive, after a three-business-day recovery threshold with documented attempts via agreed secure channels. In a signing-key-agent failure, also co-signs the client-directed recovery of assets to a replacement vault or the client’s own wallet.

Failure modes

What happens when a key partner is unavailable.

Scenario A

Tetra unavailable

Onramp MENA continues to hold the first signature; the second-signature path is paused until Tetra’s service is restored. Persistent unavailability is treated as a recovery event: under client direction, the client recovers their assets to a replacement vault or an address of their own, co-signed by the surviving Onramp MENA + Coincover quorum. Coincover does not substitute for Tetra in normal day-to-day operations.

Scenario B

Coincover unavailable

Onramp MENA + Tetra continue to sign normally. The recovery path is unavailable until Coincover service is restored, but normal operations are not affected.

Scenario C

Onramp MENA discontinuity

Tetra and Coincover hold sufficient signature material for the client to recover their assets, under client direction, to a replacement vault or an address of their own. See the recovery timeline below for the activation path.

Activation path for Scenario C: Onramp MENA discontinuity.
Recovery window | timeline
  1. DAY 0 Non-responsiveness detected
  2. THROUGHOUT Documented attempts via agreed secure channels
  3. BUS. DAY 3 Recovery activation
RECOVERY THRESHOLD | 3 BUSINESS DAYS (MAY EXCEED 72 CALENDAR HOURS)
Vault migration

Vault migration is another authorisation, never a back door.

Moving a vault follows the same quorum discipline as everything else. A client may elect to migrate at any time, authorised by the standard quorum (Onramp MENA + Tetra Trust). Where a key partner is permanently impaired, migration happens as a client-directed recovery: the client moves their assets to a replacement vault or an address of their own, co-signed by the surviving Onramp MENA + Coincover quorum, treated consistently with the other recovery scenarios rather than as ongoing operational co-signing. Either path enforces the no-privileged-exit principle on chain: there is no unilateral release path, and migration is treated as another authorisation.

Vault migration | co-signing flow

The architecture is the audit. Verifiable on chain. Not assumed at the perimeter.

Architecture in design | not yet operational