Secure, Efficient, Scalable
Top-tier, battle-tested security solutions for 260+ institutions since 2021.
RAISED
PEAK AUC
SECURELY TRANSFERRED
MPC Self-Custody
Enterprise-grade digital asset self-custody services
Eliminate single-point failures to manage digital assets
- MPC and TEE technologies protect your digital assets with the highest level of security.
- Manage wallets and transfer funds on multiple terminals, including the mobile App and Web Console.
- Policy Engine flexibly controls access authorization.
- Off-chain multisignature enhances approval privacy and significantly reduces on-chain transaction fees.
Interact with dApps under multi-party control
- Supports all public EVM-compatible blockchains and DeFi protocols.
- Policy Engine meticulously delegates transaction permissions.
- Real-time contract monitoring and phishing detection safeguard every transaction.
- Customize RPC nodes for diverse business scenarios.
- Collaboratively manage smart contract owner’s permissions to reduce single-point risk in critical operations.
Enterprise-grade digital asset self-custody services
- Seamlessly create and manage millions of MPC wallets with APIs.
- Automatic gas fuelling and sweeping significantly improve integration efficiency and accelerate your business success.
- Web3 API securely controls the entire lifecycle of smart contracts.
- API Co-Signer automates transaction approval and signing.
- MPC and TEE technologies provide multi-layer security to eliminate single-point-of-failure risk for private keys.
MPC Node Suite
White-label MPC privatization solutions
Flexibly build MPC wallets for seamless integration into your applications
- Fully privatized, with hardware-level data security and privacy protection under your control.
- A secure, universal, and cross-platform MPC-TSS key management solution.
- Support diverse business scenarios to accelerate your success.
Safest software is
open source
Safeheron independently developed MPC algorithms and is now the world's first company to open-source the mainstream MPC-TSS algorithm in C++.




Why choose us?
100% control over assets
3-of-3 MPC-TSS key management eliminates the single-point failures with full asset control.
Open-source algorithms
Safeheron open-sourced the world's first MPC-TSS algorithm library implemented in C++.
Maximum security
Safeheron’s multi-layer security defenses against state-level attacks.
Certified and insured
Safeheron is certified with ISO/IEC 27001:2022 and SOC 2 and is insured by Lockton.
Extensive features
Safeheron offers one-stop management for Web3, DeFi, NFTs, and smart contracts.
Governance and policy
TEE Policy Engine customizes multi-dimensional policies and approval workflows.
Technical support
Robust technical support encompasses use cases, solutions, technologies, and security expertise.
Diversified solutions
Battle-tested SaaS services and MPC privatization solutions.
Hear from our customers
Latest Updates from Safeheron
Safeheron Supports RD Technologies in Building a Bank-Grade Web3 Payment Security Infrastructure
Starting with merchant acquiring to drive the scalable deployment of stablecoin payments; both companies also announce deep collaboration in AI-driven financial applications. Safeheron, an institutional-grade digital asset security infrastructure provider, today announced a strategic partnership with RD Technologies, a Hong Kong-based digital fintech group. Safeheron will deliver its cutting-edge industry solutions to empower RD Technologies’ platform, providing a robust underlying security foundation for its digital wallet and account system. Concurrently, both companies will collaborate deeply on AI-empowered finance, jointly exploring frontier applications of AI technologies within institutional digital asset scenarios. Starting with Merchant Acquiring, Expanding Across Payment Scenarios The collaboration will first launch in merchant acquiring, with Safeheron supporting RD Technologies in delivering secure, compliant stablecoin payment and collection channels for merchants and enterprise users. Building on this foundation, both companies will continuously expand into a broader range of Web3 payment scenarios, progressively constructing a wider compliant payment network to meet the diversified capital flow needs of the digital economy. Joining Forces to Build a Bank-Grade Asset Security Foundation As Hong Kong’s regulatory frameworks for stablecoin and virtual assets are comprehensively implemented, compliance auditability and fund security isolation have become the core cornerstones of platform development. Through this partnership, Safeheron will leverage its profound technical expertise in digital asset custody to assist RD Technologies in building a comprehensive, high-level security […]
Etana Clients Lost 70%: The Real Failure Was the Absence ofInstitutional Asset Sovereignty
Written for risk, treasury, and compliance leaders at institutions holding digital assets. A Failure at the Highest Standard of Compliance On May 4, 2026, Payward, the parent company of Kraken, filed a second amended complaint suing its former custody partner Etana, alleging the misappropriation of $25 million in client assets. Etana was not an unlicensed operation. It held a trust company charter issued by the Colorado Division of Banking and had been a regulated “qualified custodian” since 2021, meaning registered investment advisers could legally entrust client assets to it. Etana positioned itself for four years around the marketing line “regulated global digital asset custodian.” When the firm received its charter, its CEO said it brought “peace of mind to clients.” The latest disclosure from the receiver: Etana has 6.83 million in cash against 26 million in liabilities. The nominal recovery ceiling for clients is roughly 26%. At least 70% of client assets, on paper, are gone. The Real Cost: Not 70% of the Money, but 100% of the Control For institutional clients caught in something like Etana, the three “lifelines” available are each painfully thin: The reason Kraken can sue is that it is pursuing fraud and civil theft, two claims that contractual disclaimers cannot foreclose. Most institutional clients pursuing breach-of-contract claims will find the liability was already contracted away. […]
Safeheron Achieves SOC 2 Type II Certification Again
Safeheron has once again completed its SOC 2 Type II audit and received certification. SOC 2 Type II is an independent security audit framework established by the American Institute of Certified Public Accountants (AICPA), assessing service organizations across three trust service criteria: security, availability, and confidentiality. Unlike a point-in-time evaluation (Type I), Type II requires auditors to examine whether controls operate consistently over an extended period — typically six to twelve months. It tests execution, not just documentation. This audit was conducted by one of the Big Four accounting firms. Passing this audit is not a formality for us. It is a real test of whether our internal standards hold up to independent scrutiny — across key management, access controls, system availability, and data confidentiality. Each time we pass, it reflects the work put in before the auditors arrive. A current certification verified by a globally recognized audit firm is our most concrete commitment to security, not just a claim. For more information on our compliance certifications, please contact our team.
Safeheron and Embed Financial Group Holdings (EFGH) Announce Strategic Partnership to Deliver Ultimate Key Sovereignty for VNL1 and Sovereign Finternets
SINGAPORE — May 8, 2026 — Embed Financial Group Holdings (“EFGH”), a premier provider of next-generation financial infrastructure, today announced a strategic partnership with Safeheron, a pioneer in institutional-grade digital asset custody solutions. This collaboration will integrate Safeheron’s advanced MPC-TEE-HSM architecture into EFGH’s sovereign chain projects, establishing an uncompromised standard for security and key sovereignty, beginning with the Vietnam Layer One (VNL1) network. As nations and institutions transition toward decentralized financial systems under the “Finternet” framework, the requirements for data localization and cryptographic control have become paramount. For national-scale infrastructure like VNL1, standard SaaS custody models—where a vendor retains a key shard—are often insufficient. Sovereign networks require absolute, uncompromising control over their own cryptographic material. Through this partnership, EFGH will leverage Safeheron’s On-Premise Full Platform. This deployment model ensures that all key shards are held exclusively by the deploying institution, with Safeheron holding zero shards. This guarantees that critical data never leaves the bank-controlled or sovereign infrastructure. “When we build sovereign Finternets, true autonomy means holding your own keys at the foundational layer,” said Chia Hock Lai, Asia CEO at EFGH. “Safeheron’s architecture allows us to deploy VNL1 with absolute key sovereignty. What’s truly exciting is that we are seeing rapidly increasing demand for exactly this type of highly customized, sovereign infrastructure in jurisdictions far beyond Vietnam. Governments and regulated […]
The $300M Lost Post-Mortem: The Institutional Trust Chain Doesn’t End at Multisig
Multisig Was in Place, and the Attack Still Succeeded Two major security incidents recently shook the crypto industry. Resolv Labs and Drift collectively lost over $300 million. The Resolv incident is relatively straightforward: critical assets were managed by a single private key. Once that key was compromised, $25 million was drained. This type of attack has precedent, and established countermeasures exist. The Drift incident is more unsettling. Drift is a protocol that had deployed a multisig scheme. In the security calculus of many institutions, multisig is practically synonymous with “we’ve done our due diligence.” But the attackers didn’t crack any keys or circumvent the signing mechanism. Instead, they got the signers to sign voluntarily — and held onto those pre-signed transactions for later execution. A timelock was supposed to serve as a buffer. Even if a malicious transaction were triggered, the delay window would give the community time to detect and intervene. But governance had already changed the configuration to Zero Timelock before the attack. The buffer vanished, and the stockpiled signatures became immediately executable. The multisig mechanism remained intact. The protection was gone. Both incidents point to the same underlying problem: digital asset security is not about whether multisig is in place — it’s about whether every link in the trust chain is effectively constrained. Resolv: One Minting Key, […]

