Security & Key Management

No single point of key compromise.

Regulated by Securities Commission Malaysia

Every GamBit Custody product — institutional, enterprise and Legacy Vault — runs on one security architecture: the C.H.A.I.N. framework. This page is the full detail behind the claim.

Talk to us
The framework

C.H.A.I.N. — five layers, defence in depth.

Each layer assumes the one outside it can fail. An attacker who breaches the network perimeter still faces policy enforcement, segregated access, MPC signing and offline key material.

Cryptographic security

Key parts are stored off-line in secure enclaves.

Hot wallet MPC

Keys encrypted within secure enclaves enable fast and secure transaction authorisation.

Access control

Strict segregation of access prevents malicious alteration or transaction.

Integrated policy modules

Verify user access and roles, enforce transaction limits and compliance.

Network perimeter defences

Protecting outer boundaries to prevent unauthorised access and breaches.

+ Plus cold wallet MPC: interacting with cold-stored assets requires a physical offline key, secured by GamBit, to complete the MPC process.
Layer by layer

What each layer actually does.

Cryptographic security

Private keys never exist whole. Key parts are generated and stored off-line in secure enclaves, so there is no single artifact to steal, copy or lose. Cold-stored assets add a physical offline key — secured by GamBit — that must participate before anything moves.

Hot wallet MPC

Operational wallets sign with multi-party computation: keys encrypted within secure enclaves cooperate to authorise transactions quickly, without ever reconstructing a complete key on any single machine.

Access control

Every user is individually hardened — multi-factor authentication, IP address whitelisting and role-scoped permissions. Strict segregation of access prevents malicious alteration or transaction, and distinct Controller and Responsible Person functions keep authority divided.

Integrated policy modules

Governance is enforced by the platform, not by promises: policy modules verify user access and roles, enforce transaction limits, and require maker-checker approval quorums before value moves.

Network perimeter defences

The outer boundary is defended in depth to prevent unauthorised access and breaches — and validated continuously by independent penetration testing, not just internal review.

Operational security

Security is a practice, not a feature list.

Independent penetration testing

External specialists attack our infrastructure on a recurring cadence; findings are remediated and retested.

Key ceremonies under dual control

Key generation and recovery follow documented ceremonies with segregation of duties and witnesses.

Continuity & recovery

Disaster-recovery and business-continuity procedures cover the custody platform and signing infrastructure.

Compliance, integrated

Compliance runs inside the transaction flow.

Checks, monitoring and reporting aren't bolted on after the fact — they're part of how every transaction executes.

  • Segregation of duties — Distinct Controller and Responsible Person functions, with strict segregation of access to prevent malicious alteration or transaction.
  • Independent penetration testing — Our infrastructure is independently penetration-tested — security claims verified by outside specialists, not just internal audits.
  • Integrated compliance — Compliance checks, transaction monitoring and automated reporting on holdings, transaction history and portfolio activity — built in, not bolted on.

Put your assets behind C.H.A.I.N.

Whichever product fits you, the security architecture is the same.

Talk to us