We design, build, and audit Bitcoin custody — for individuals, families, and companies.
Custody that survives lost devices, bad days, and time. We design it around your threat model, build it with you in the room, and rehearse it until it works under stress. We also build Coinhost Wallet, a 2-of-3 multisig app, on the same principles.
Every project is different, but the work falls into a small number of categories. If you're not sure which one you need, start with the free consultation and we'll point you to the right one.
A signing scheme designed around what you hold, who can act, and which failures the design must survive. Documented and built to be operated by ordinary humans.
2 – 4 weeksDevice selection, initialisation in controlled conditions, key generation we attest to, and a structured handover. You leave knowing exactly what you hold and how to use it.
1 – 2 weeksA written review of what you currently have: signers, locations, redundancies, single points of failure, recovery paths. A report and a prioritised fix list. Many clients start here.
1 – 3 weeks · Fixed feePhased withdrawal plans for sizable balances: timing, settlement, address hygiene, post-move verification. The transition off third parties, made boring and documented.
2 – 6 weeksA plan that survives you: distributed keys, written instructions, a known executor path — and a rehearsal that proves it works while you are alive to fix it.
3 – 6 weeks · With counselControlled recovery exercises — lost device, lost signer, compromised key — and closed-room training for teams, until everyone can execute without us in the room.
Days · RecurringNot sure where to start? Book the free 30-minute consultation. We'll tell you what you actually need — even if the answer is "you don't need us yet".
Book a consultationA consistent process is what separates a custody plan you can execute under stress from one that lives on a slide.
A confidential conversation, then a written brief: what you hold, what you fear, who else needs access.
One or two custody designs with the trade-offs spelled out — signers, locations, recovery paths. You choose.
Hardware initialised, keys generated and distributed, wallet stood up, addresses verified. Every step witnessed.
Controlled drills against the live setup: signing, partial loss, full recovery. We leave when you can run it alone.
Our consultancy is software-agnostic — we set up whatever is right for you. But for many clients the right tool is the one we build ourselves: a 2-of-3 multisig wallet with no seed phrases to lose and no single point of failure.
Mt. Gox, QuadrigaCX, FTX, Celsius. Every cycle has its names, and the pattern repeats: assets pooled with a counterparty, recovered cents on the dollar — if at all.
A single-key wallet has a single point of failure: lose the seed phrase, lose the coins. Most well-intentioned setups collapse on the first unrehearsed test.
A well-designed multisig removes the single point of failure. "Well-designed" is the hard part — and it's the part we do.
Write a few lines about what you hold and what concerns you. We reply within two working days, and the first conversation costs nothing.
All conversations are confidential. Client identities are never published.