shielded custody assurance
integration review for autonomous systems that handle real capital.
Recent open-source work
ctaz-explorer same-day shipping arc on Zcash Crosslink (live finalizer participation crawler, per-block PoW↔PoS visualizer, staking-window indicator). RFC at crosslink_monolith issue #16 proposing community observability RPCs. Community PR at crosslink_monolith PR #17 on the s1_dev branch fixing a mempool backoff bug, cargo check clean. Upstream PR at librustzcash #2278 merged (transparent sighash hardening). ZAP1 attestation protocol deployed on 6 mainnet chains plus NEAR and Sui.
What you get
1. Split-key wallet
Ika 2PC-MPC wallet provisioned for your agent. Your key share stays with you. Agent key share deployed to your infrastructure. No single party can drain.
2. On-chain policy
Spend limits, daily caps, whitelisted destinations, withdrawal ceilings. Defined with you. Enforced on-chain via Sui Move. The agent cannot override its own rules.
3. Attestation integration
Every agent action produces a BLAKE2b Merkle leaf. Roots anchored to Zcash mainnet. Proof bundles verifiable on 6 chains. Event types configured to your workflow.
4. Kill switch
FROST 2-of-3 threshold. You hold the revocation key. One call halts the agent, freezes funds, attests shutdown on-chain. The agent cannot prevent its own termination.
5. MCP toolchain
22 tools across zcash-mcp, openclaw-zap1, zcash-402, zcash-ika. Installed and configured for your runtime. LLM host choice stays on your side.
Timeline
Week 1
Wallet provisioning + policy definition. Key ceremony (30 min call).
Week 2
Attestation integration + event type configuration + testing.
Week 3
Kill switch deployment + monitoring + alerting + go-live.
Week 4
Burn-in period. Daily attestation reports. Policy tuning.
Pricing
Builder
$49
/month
API access
100 leaves/day
Auto-anchor + webhooks
Dashboard + email support
Operator
$299
/month
Unlimited leaves
Cross-chain verification
Custom event types + webhook
99.5% SLA
Custody
$999
/month
Managed dWallet + signing
Sui Move policy + FROST
Compliance exports + eng support
99.9% SLA
Self-serve attestation access tiers are shown here. Larger custody reviews scope separately.
What we need from you
Agent runtime environment (where your agent runs).
Spend policy requirements (daily limits, allowed destinations).
Preferred notification channel (Signal, webhook, email).
Key ceremony participation (30 min video call for FROST share distribution).
Open spec
The verifier and attestation path are defined by a
public spec under CC-BY-4.0. You can audit, self-host, or extend at any time. Attestation proofs remain portable and independently checkable.