The 24-hour time-lock
Every withdrawal starts a 24-hour clock before keys unlock. A legitimate withdrawal costs a day of patience; a stolen phone buys an attacker a day of warnings instead of your funds.
Instant cancel, zero approvals
Cancelling needs no quorum and no waiting — stopping money is always easier than moving it. Any guardian can kill a request at any point in the 24 hours, and the cancellation is logged for all of them.
Guarded whitelist changes
Adding an address is itself a time-locked operation: 48 hours before first use, every guardian alerted on the spot. The obvious attack — whitelist yourself first, withdraw second — costs two full rounds of the same gauntlet.
Labels and networks
Whitelist entries carry human labels — main wallet, hardware vault, studio treasury — beside their addresses and networks. Removing an address is effective instantly; only additions wait.
Hardware-key approval
A hardware key can stand as a guardian: plug in to approve. One approval stays entirely off the phone, so a compromised device cannot cast two votes.
Guardian check-in
Guardians confirm reachability on a 90-day cycle, and the vault shows when each was last verified. A guardian who has gone quiet is a fact you learn on schedule — not during an emergency.
Guardian alerts
Every withdrawal request notifies all guardians immediately — not just the two who need to approve. The alarm is collective by design: three people see a theft attempt, not one.
Replacing a guardian
People change phones and drift away, so replacement is a first-class flow: a 48-hour time-lock and two approvals from the existing quorum. An attacker cannot swap your guardians out quietly.
New-device flags
A request from a device the vault has not seen before is flagged as such, right on the approval screen. Guardians judge the request with that context in front of them.
Self-custody keys
The keys are yours — generated and held by you, never by Protocore. Safe adds process around your keys; it does not take custody of them.
Multi-asset cold storage
One vault holds BTC, ETH, and USDC — 0.42 BTC, 12.4 ETH, and 1,150 USDC in the demo. Moving funds to the Safe is one action, and every asset inherits the same three protections.
Fiat value before release
A pending withdrawal states its fiat value before anything is released — the request screen says so in plain text. What leaves the vault is never a surprise denominated only in coins.
Verified seed backup
The seed backup is not a checkbox — it carries a verification date, and the demo's was confirmed against a steel plate. A backup you have proven beats a backup you believe in.
The 72-hour recovery lock
Recovery re-issues keys to a new device only after a 72-hour time-lock — three times the withdrawal window. Taking over a vault is strictly slower than emptying one, and emptying one takes a day plus two guardians.
Recovery drills
Run the entire recovery with test keys — guardians participate, nothing moves. The demo's last drill was 118 days ago, and the screen says so; a recovery you have rehearsed is one you can execute under stress.
The activity log
Additions, removals, cancellations, approvals — the vault keeps the last 30 days on-screen and every event on the record, attributed to who did it. Guardians audit the vault by scrolling.
Nothing hidden from guardians
Every request, cancellation, and policy change is visible to all three guardians, not just the parties involved. A quorum can only protect what it can see.
The same model as the treasury
Safe applies to individuals the custody model Protocore Chain runs for treasuries: quorum signing, time-locks, and known destinations. One security philosophy, personal scale.
Whitelabel vault
Safe ships standalone or as a vault inside your own product — your brand on the screens, the same time-lock, quorum, and whitelist underneath. Cold storage becomes a feature you offer, not a company you build.