/// Safe · Self-custody

Security that spends time instead of trust

Hot wallets lose funds in seconds. Safe makes every withdrawal take 24 hours, two guardians, and a known address — three independent things an attacker must beat.

24h
Withdrawal time-lock
2-of-3
Guardian approvals
Whitelist
Approved addresses only
Yours
Self-custody keys
/// 01

The time-lock is the alarm

A withdrawal request starts a 24-hour clock, visible to you and your guardians. A legitimate withdrawal is a day of patience; a fraudulent one is a day of warning — plenty of time to cancel a request you never made.

/// 02

Guardians and the whitelist

Funds move only when 2 of 3 guardians approve, and only to addresses already on the whitelist. Adding a new address is itself a guarded, time-locked operation — so an attacker cannot simply whitelist themselves first.

  • [ 01 ]2-of-3 approval — no single point of compromise
  • [ 02 ]Whitelist changes go through the same gauntlet
  • [ 03 ]Self-custody throughout: your keys, your guardians
/// Features
Cold storage at a glance — balances and every protection on one screen.
/// 01

The vault

The vault screen shows €48,210 in cold storage across Bitcoin, Ethereum, and USD Coin — keys offline, air-gapped. All three protections sit on the same screen: time-lock on, 2-of-3 guardians, whitelist only. Nothing about the security hides in a settings page.

The clock running — approvals, destination, and cancel in one view.
/// 02

A withdrawal in flight

Request 9F21-0716 moves 0.10 BTC — about €6,124 — and the screen shows every layer working: 23:41:02 until keys unlock, one of two required approvals in, destination verified against the whitelist. Cancel stays one tap away the entire time.

The quorum — three guardians, two must approve, changes time-locked 48h.
/// 03

The guardian quorum

Three guardians, two must approve — the policy sits at the top of the screen, not in fine print. The demo quorum mixes key types on purpose: this phone, a second person's phone key, and a hardware key last seen on 14 July. Changing the quorum is itself time-locked for 48 hours.

  • [ 01 ]2-of-3 across independent key types
  • [ 02 ]Guardian status and last-seen visible at a glance
  • [ 03 ]Quorum changes time-locked 48h
Approved destinations only — a new address waits 48h before first use.
/// 04

The whitelist

Four labeled destinations across Base, Bitcoin, Ethereum, and Solana — three active, one still counting down. Withdrawals can only travel to addresses on this list, and a new entry waits 48 hours before first use, with every guardian alerted the moment it is added.

One tap kills it — cancelling is instant, approvals are not.
/// 05

Cancelling a request

The withdrawal on this screen came from a guardian's account on a new device — exactly the request you want to be able to kill. One tap voids it: the 0.10 BTC stays in cold storage, all three guardians are notified, and the requester cannot restart it without a fresh quorum. No fees, no waiting, logged for everyone.

Three ways back in — seed, guardians, hardware, all drillable.
/// 06

Recovery, rehearsed

Three configured ways back in: a seed backup verified against a steel plate, guardian recovery where 2 of 3 restore access from any device, and a sealed hardware key stored off-site. Re-issued keys wait out a 72-hour time-lock, and a drill runs the whole flow with test keys — guardians included, nothing moves.

  • [ 01 ]Seed, guardians, and hardware — three independent paths
  • [ 02 ]Guardian recovery works from any device
  • [ 03 ]72h time-lock before keys re-issue
/// And more

The 24-hour time-lock

Every withdrawal starts a 24-hour clock before keys unlock. A legitimate withdrawal costs a day of patience; a stolen phone buys an attacker a day of warnings instead of your funds.

Instant cancel, zero approvals

Cancelling needs no quorum and no waiting — stopping money is always easier than moving it. Any guardian can kill a request at any point in the 24 hours, and the cancellation is logged for all of them.

Guarded whitelist changes

Adding an address is itself a time-locked operation: 48 hours before first use, every guardian alerted on the spot. The obvious attack — whitelist yourself first, withdraw second — costs two full rounds of the same gauntlet.

Labels and networks

Whitelist entries carry human labels — main wallet, hardware vault, studio treasury — beside their addresses and networks. Removing an address is effective instantly; only additions wait.

Hardware-key approval

A hardware key can stand as a guardian: plug in to approve. One approval stays entirely off the phone, so a compromised device cannot cast two votes.

Guardian check-in

Guardians confirm reachability on a 90-day cycle, and the vault shows when each was last verified. A guardian who has gone quiet is a fact you learn on schedule — not during an emergency.

Guardian alerts

Every withdrawal request notifies all guardians immediately — not just the two who need to approve. The alarm is collective by design: three people see a theft attempt, not one.

Replacing a guardian

People change phones and drift away, so replacement is a first-class flow: a 48-hour time-lock and two approvals from the existing quorum. An attacker cannot swap your guardians out quietly.

New-device flags

A request from a device the vault has not seen before is flagged as such, right on the approval screen. Guardians judge the request with that context in front of them.

Self-custody keys

The keys are yours — generated and held by you, never by Protocore. Safe adds process around your keys; it does not take custody of them.

Multi-asset cold storage

One vault holds BTC, ETH, and USDC — 0.42 BTC, 12.4 ETH, and 1,150 USDC in the demo. Moving funds to the Safe is one action, and every asset inherits the same three protections.

Fiat value before release

A pending withdrawal states its fiat value before anything is released — the request screen says so in plain text. What leaves the vault is never a surprise denominated only in coins.

Verified seed backup

The seed backup is not a checkbox — it carries a verification date, and the demo's was confirmed against a steel plate. A backup you have proven beats a backup you believe in.

The 72-hour recovery lock

Recovery re-issues keys to a new device only after a 72-hour time-lock — three times the withdrawal window. Taking over a vault is strictly slower than emptying one, and emptying one takes a day plus two guardians.

Recovery drills

Run the entire recovery with test keys — guardians participate, nothing moves. The demo's last drill was 118 days ago, and the screen says so; a recovery you have rehearsed is one you can execute under stress.

The activity log

Additions, removals, cancellations, approvals — the vault keeps the last 30 days on-screen and every event on the record, attributed to who did it. Guardians audit the vault by scrolling.

Nothing hidden from guardians

Every request, cancellation, and policy change is visible to all three guardians, not just the parties involved. A quorum can only protect what it can see.

The same model as the treasury

Safe applies to individuals the custody model Protocore Chain runs for treasuries: quorum signing, time-locks, and known destinations. One security philosophy, personal scale.

Whitelabel vault

Safe ships standalone or as a vault inside your own product — your brand on the screens, the same time-lock, quorum, and whitelist underneath. Cold storage becomes a feature you offer, not a company you build.

/// In the product
/// FAQ

Self-custody, answered.

  • Losing one key does not lock you out — the quorum is 2-of-3, so two of the three still move funds. Recovery runs three ways: a seed backup, 2-of-3 guardian recovery, and a sealed off-site hardware key, each with a practice drill so you learn it works before you need it.

  • No. Every withdrawal is time-locked for 24 hours, needs 2-of-3 guardian approval, and can only go to a whitelisted address — and a request you never made can be cancelled instantly while the clock runs. One stolen device beats none of those.

  • You do. Safe is self-custody: keys are generated and held by you and your guardians, never by us. We cannot move your funds, and neither can anyone who compromises a single device.

  • Deliberately not. Adding a whitelisted address is itself a guarded, time-locked change — 48 hours in the demo — so an attacker cannot add their own address and withdraw to it. The friction is the protection.

  • A day. The 24-hour time-lock is the alarm: a real withdrawal is a day of patience, a fraudulent one is a day of warning. Cancelling is instant even though approving is not — the asymmetry favors the owner.

/// Evaluate

Try the vault before you trust it.

[ 01 ]

Guided demo walkthrough

We walk a withdrawal end to end — the 24-hour time-lock, 2-of-3 guardian approval, and the whitelist — including cancelling a request you never made.

[ 02 ]

Sandbox vault

A test vault where your team can set guardians, add a whitelisted address, and start and cancel a time-locked withdrawal.

[ 03 ]

Guardian test devices

Enrol test devices as guardians to see the 2-of-3 quorum and the time-locked whitelist changes in practice.

[ 04 ]

Standalone or embedded

Evaluate as a standalone vault or as a whitelabel vault inside your own product — self-custody throughout.

Availability

Available standalone or as a whitelabel vault inside your own product.

In the ecosystem

Safe applies Chain's treasury custody model — quorum, time-locks, known destinations — at personal scale, holding what Wallets transacts with.

Pick a product. Or take the core.

Everything above runs in production demos we can walk you through — standalone, whitelabel, or as one platform. Tell us what you're building and we'll show you the shortest path to it.

Contact us