/// Chain · Blockchain Rails

The chain is a rail, not a destination

Chain exists so the rest of the family can treat blockchains as plumbing: value arrives on-chain and leaves as euros in an IBAN, in one flow.

Multi-chain
All major blockchains
1 flow
On-chain →︎ IBAN
2-of-3
Treasury signers
External
Wallet connect
/// 01

Bring your own wallet

Customers connect the wallets they already hold — no forced migration into a new one. From there, an on-chain payment settles and bridges to an IBAN in a single flow: the sender sees a blockchain transaction, the recipient sees euros arrive.

/// 02

Treasury without single signers

The treasury console holds balances across BTC, ETH, Base, and Solana in one view, and every treasury operation requires 2 of 3 signers. Multi-chain custody with no individual able to move funds alone.

  • [ 01 ]Four chains in one console
  • [ 02 ]2-of-3 signing on every treasury move
  • [ 03 ]The same custody model Safe applies to individuals
/// Features
Three ways in — extension, WalletConnect, or hardware, keys staying where they are.
/// 01

External wallet connect

Customers bring the wallet they already hold — a browser extension, a mobile wallet over WalletConnect, or a hardware wallet that signs on-device. No forced migration, no new seed phrase. Connecting takes a minute and covers every supported network at once.

  • [ 01 ]Browser, WalletConnect, and hardware wallets
  • [ 02 ]Hardware keys never leave the device
  • [ 03 ]One connection across all supported networks
One flow — USDC confirms on Base, euros land in the IBAN.
/// 02

On-chain to IBAN

One flow carries value from a blockchain to a bank account. In the demo, a USDC transfer confirms on Base and settles to IBAN RO49 ···· 0421 by instant SEPA. No manual off-ramp, no second product: the sender sees a transaction, the recipient sees euros.

Four chains, one console — balances, policies, and signers in a single view.
/// 03

Multi-chain treasury

€4,204,319 in custody across the major chains, in one view. Each asset carries its own policy — an operational USDC hot wallet, bitcoin in cold storage, 2-of-3 on the rest — and signer status updates live as approvals come in. Recent settlements sit right beside the balances they came from.

  • [ 01 ]BTC, ETH, Base, and Solana in one console
  • [ 02 ]Per-asset custody policy on the balance sheet
  • [ 03 ]Live signer status on pending approvals
Everything before confirm — destination, fee, total, fiat value shown.
/// 04

Confirm before send

A send states everything before it happens: destination, network, network fee, and total — 0.052 ETH with its fiat value shown right under the amount in the demo — plus a plain warning that a mainnet transfer cannot be reversed. Nothing moves until the user has read what will.

The bridge, live — confirmations on one side, instant SEPA on the other.
/// 05

The bridge, end to end

The settlements console watches every transfer cross: €18,410.10 paid out today, three in flight, 128 settled over seven days, median chain-to-IBAN time 4m 32s. Each row carries its transaction hash, live confirmation count, and EUR payout — the conversion rate is shown before each bridge is confirmed, and the EUR amount locks at payout.

  • [ 01 ]Per-transfer hashes, confirmations, and payout status
  • [ 02 ]Rate shown before confirm; EUR locked at payout
  • [ 03 ]Recent payouts tied to the IBAN they landed in
2-of-3 in practice — devices, pending signatures, time-locked changes.
/// 06

Signers, on the record

The signing page shows the 2-of-3 policy as it lives: three enrolled devices — a hardware key, a phone key in a secure enclave, and an HSM that co-signs but never initiates — with last-signed times and status. Two operations sit awaiting a second signature, one of them a 12,500.00 USDC move to the cold vault, expiring if nobody signs.

Four lanes, live health — congestion, confirmations, incidents on the record.
/// 07

Network status

Four lanes, live: congestion per network, deposit address, confirmations required before payout, and operational state — 3 of 4 in the demo, with Solana recovering from an RPC incident while deposits stay safe. The incident log keeps the last 30 days honest, and Alert me subscribes you to changes.

The rail's vitals — stuck, failed, and held on one screen, breakers live.
/// 08

The operator's crypto overview

The rail's vitals on one screen: three stuck top-ups pending, two failed in 24 hours, one P2P transfer held for review — each a click from its queue. Below, per-provider health with circuit-breaker states: chain-rpc closed, exchange-bridge half-open, btc-node idle, refreshed every ten seconds.

Deposit to fiat, accountable — the full trail behind every credit.
/// 09

Top-ups to fiat, accountable

Every on-chain deposit credited to a fiat balance keeps its full trail: wallet address, transaction hash, order and exchange ids, the rate and fee recorded at settlement, and the owner it credited. The demo drawer shows 250.00 USDC arriving on Base and crediting €238.62 two minutes later — with a guarded reverse-and-refund for the cases support escalates.

/// And more

2-of-3 signing

Treasury moves above €10,000 require two of three signers — no individual moves funds alone. Below the threshold, the hot key auto-signs so operations keep flowing, and an HSM key stands by as the third signer. The same custody model Safe applies to individuals.

Confirmation tracking

Every settlement shows its life in real time: submitted, on-chain with a live confirmation count — 3 of 12 in the demo — then settled. Transaction hash, network fee, and reference sit one tap away, with a direct link to the explorer.

Read-only connections

Connecting a wallet shares balances and addresses — nothing else. Every transfer is signed in the customer's own wallet, approved one at a time. The platform can watch; only the customer can move.

Instant SEPA payout

The bridge ends in a bank account, fast. The demo's USDC transfer was submitted at 14:02 and settled to its IBAN at 14:06 over SEPA Instant — euros in the account in four minutes, no manual step in between.

Hot and cold tiers

Custody policy is set per asset, not per account. The demo treasury keeps operational USDC in a hot wallet, bitcoin cold, and everything else behind 2-of-3 — each tier visible on the balance sheet it governs, including internal moves to the cold vault.

Four networks

BTC, ETH, Base, and Solana, with stablecoin settlement where it matters — the demo settles USDC on Base. One console, one policy model, one bridge to IBAN across all of them.

Rate shown before you confirm

No bridge executes on a rate the customer has not seen: the conversion rate is shown before each bridge is confirmed, and the EUR amount locks at payout. The mechanics are the promise — never a number we quote in advance.

Per-network confirmation policy

Each lane pays out after its own confirmation count — 6 on Bitcoin, 12 on Ethereum and Base, 32 on Solana in the demo. Finality is a per-network judgment, not a global constant.

Deposit address rotation

Deposit addresses rotate per invoice and display masked, with the full address available over the API. A payment ties to the invoice that expected it — reconciliation by construction.

Incidents and alerts

Degraded RPC, elevated congestion, node maintenance — the incident log records each with its window and its impact, and status alerts push changes to whoever subscribed. Bad news travels on the same rail as good.

Circuit breakers

Every provider behind the rail runs behind a breaker — closed when healthy, half-open while recovering, idle when out of rotation. Health is a state machine you can read, refreshed every ten seconds.

Stuck top-up recovery

A deposit that confirmed on-chain but stalled at the exchange step is a queue, not a mystery: stuck top-ups surface on the overview, and an operator requeues the exchange in place. The customer's money finishes the trip.

Reverse and refund

When a credit must come back, the reversal posts a compensating debit on the ledger and refunds on-chain — a real accounting entry, not a deletion. The action is role-gated to senior operators and lands in the audit log.

Key rotation

Signer keys rotate as an operation like any other: proposed, quorum-signed, and executed on a delay — the demo's phone-key re-issue executes 24 hours after quorum. Rotation history keeps every past key event on the record.

Time-locked policy changes

Changing signers or the threshold is itself time-locked for 48 hours, and every signer is alerted when it is proposed. The policy that guards the funds guards itself the same way.

Expiring proposals

A pending operation that never collects its second signature expires — 22:41:02 left on the demo's cold-vault transfer. Stale intentions die on their own instead of waiting to be exploited.

Exports

Transfers export straight from the settlements console — hashes, confirmations, payouts, and references, ready for accounting or an auditor. The bridge's history is a file you can hand over.

The family's shared rail

Chain is the rail the rest of the product family settles crypto on — on-ramps, ATM purchases, and wallet balances all cross the same bridge. Run it standalone, or let it do its quiet work underneath the other products.

/// In the product
Connect — customers bring the wallet they already have.
Settle — on-chain confirmation bridging straight to an IBAN.
The treasury — every chain in one console, 2-of-3 signers.
Everything before confirm — destination, fee, total, fiat value shown.
The rail's vitals — stuck, failed, and held on one screen, breakers live.
Deposit to fiat, accountable — the full trail behind every credit.
/// FAQ

On-chain to IBAN, answered.

  • All the major blockchains. The demo treasury shows BTC, ETH, Base, and Solana in one console, and the network board tracks each lane's congestion and confirmation policy — but the rail is not fixed to a set list.

  • No. Value arrives on-chain and leaves as euros in an IBAN, in a single flow — the sender sees a blockchain transaction, the recipient sees euros land. Chain treats the blockchain as plumbing, not a destination.

  • Each network has its own confirmation policy — a payout waits for the confirmation threshold set for that chain before it bridges. A fast L2 and Bitcoin do not wait the same amount of time, and the network board shows the threshold per lane.

  • No — they connect the external wallet they already hold, with no forced migration into a new one. From there the on-chain payment settles and bridges to an IBAN in one flow.

  • No single signer. Every treasury operation requires 2 of 3 signers, and policy changes are time-locked — the same custody model Safe applies to individuals, here across a multi-chain treasury.

/// Evaluate

Settle on-chain into an IBAN.

[ 01 ]

Guided demo walkthrough

We walk a payment from an external wallet to a euro payout — on-chain confirmation bridged to an IBAN in one flow — plus the multi-chain treasury.

[ 02 ]

Sandbox account

A test environment to connect a wallet, run a settlement on testnets, and watch it bridge to a test IBAN.

[ 03 ]

API access, webhooks, and docs

The settlement and treasury APIs, event webhooks, and docs — enough to wire on-chain settlement into your own flow.

[ 04 ]

Treasury test signers

Enrol test devices to see 2-of-3 signing and the time-locked policy changes on treasury operations.

Availability

Runs standalone or whitelabel, alongside the rest of the family or on its own.

In the ecosystem

Chain settles crypto for the whole family — Gateway and PoS acceptance, Ramp and ATM exchange, Wallets balances — and Safe is its treasury custody model at personal scale.

Pick a product. Or take the core.

Everything above runs in production demos we can walk you through — standalone, whitelabel, or as one platform. Tell us what you're building and we'll show you the shortest path to it.

Contact us