Built on the proven SSP Wallet foundation β extending 2-of-2 multisig security to multi-party business coordination
SSP Enterprise transforms the battle-tested SSP Wallet ecosystem into a comprehensive multi-party cryptocurrency management solution for businesses, partnerships, and organizations. While maintaining the core principle of true self-custody, SSP Enterprise adds business-grade coordination features on top of the proven 2-of-2 multisignature architecture that has secured user funds since 2024.
SSP Enterprise extends the revolutionary SSP Wallet ecosystem β a BIP48 true 2-of-2 multisignature crypto wallet that's already securing millions in digital assets β to multi-party business scenarios. Instead of a single user controlling two devices (browser + mobile), SSP Enterprise coordinates multiple parties, each with their own SSP Wallet + SSP Key setup.
The SSP ecosystem consists of three battle-tested components:
Security Track Record: Halborn security audit passed with clean results (March 2025)
Single User with 2-of-2 Multisig Security:
βββββββββββββββββββ βββββββββββββββββββ
β SSP Wallet β β SSP Key β
β (Browser Ext) βββββΊβ (Mobile App) β
β β β β
β β’ One private β β β’ Second privateβ
β key stored β β key stored β
β β’ Transaction β β β’ Biometric/PIN β
β construction β β confirmation β
β β’ BIP48 paths β β β’ Final signing β
βββββββββββββββββββ βββββββββββββββββββ
β β
βββββ SSP Relay βββββββββ
(Communication Only)
β
Live and securing user funds since 2024
β
15+ blockchain networks supported
β
WalletConnect v2, Account Abstraction (ERC-4337)
β
Halborn security audit passed (100% issues resolved)
Each Party Uses Their Own SSP Wallet + SSP Key (2-of-2):
βββββββββββββββββββββββ βββββββββββββββββββββββ βββββββββββββββββββββββ
β Party A β β Party B β β Party C β
β (Uses SSP Wallet β β (Uses SSP Wallet β β (Uses SSP Wallet β
β ecosystem) β β ecosystem) β β ecosystem) β
β βββββββββββββββββββ β β βββββββββββββββββββ β β βββββββββββββββββββ β
β β SSP Wallet β β β β SSP Wallet β β β β SSP Wallet β β
β β (Browser Ext) β β β β (Browser Ext) β β β β (Browser Ext) β β
β βββββββ¬ββββββββββββ β β βββββββ¬ββββββββββββ β β βββββββ¬ββββββββββββ β
β β β β β β β β β
β βββββββ΄ββββββββββββ β β βββββββ΄ββββββββββββ β β βββββββ΄ββββββββββββ β
β β SSP Key β β β β SSP Key β β β β SSP Key β β
β β (Mobile App) β β β β (Mobile App) β β β β (Mobile App) β β
β βββββββββββββββββββ β β βββββββββββββββββββ β β βββββββββββββββββββ β
βββββββββββββββββββββββ βββββββββββββββββββββββ βββββββββββββββββββββββ
β β β
ββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββ
β
βββββββββββββββββββββββββββββββββββββββββββ
β SSP Enterprise Platform β
β (New Business Coordination) β
β β
β π Web portal for business management β
β π Multi-party address generation β
β π Transaction proposal & approval β
β π Business policy engine β
β π Audit trails & compliance reporting β
β π₯ Role-based access control β
β π Integrates with existing SSP infra β
βββββββββββββββββββββββββββββββββββββββββββ
Key Innovation: SSP Enterprise leverages the existing, proven SSP ecosystem. Each business party continues using their familiar SSP Wallet + SSP Key setup, with the Enterprise platform coordinating multi-party decisions on top.
SSP Enterprise maintains the core security principle of never storing private keys or sensitive data, while enabling seamless business coordination:
Data Storage Model:
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β SSP Enterprise Data Architecture β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β
β β NEVER STORED (Remains on user devices): β
β βββ Private keys (stay in SSP Wallet/Key) β
β βββ Seed phrases (user-controlled) β
β βββ Transaction signing data β
β βββ Sensitive authentication tokens β
β β
β β
COORDINATION DATA (Stored in SSP Relay): β
β βββ Public keys for address generation β
β βββ Multi-party wallet addresses β
β βββ Business policy configurations β
β βββ Transaction proposals (unsigned) β
β βββ Approval workflows and status β
β βββ Audit trails and compliance logs β
β βββ User roles and permissions β
β β
β π SECURITY BENEFITS: β
β βββ Enables seamless enterprise integration β
β βββ Facilitates analytics and reporting β
β βββ Maintains true self-custody principles β
β βββ Zero risk of private key exposure β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Security Assurance: All stored data is non-sensitive by design. Even if the SSP Enterprise platform were compromised, no private keys or funds would be at risk since all signing operations occur on user-controlled devices.
Each blockchain network has different technical capabilities, requiring tailored approaches:
Structure: 4-of-6 Multisig (Technical Reality)
βββββββββββββββ βββββββββββββββ βββββββββββββββ
β Party A β β Party B β β Party C β
βββββββββββββββ€ βββββββββββββββ€ βββββββββββββββ€
β Wallet A β β Wallet B β β Wallet C β
β Key A β β Key B β β Key C β
βββββββββββββββ βββββββββββββββ βββββββββββββββ
Why 4-of-6: Bitcoin's ECDSA cannot combine signatures
Bitcoin Script: OP_4 <WA> <KA> <WB> <KB> <WC> <KC> OP_6 OP_CHECKMULTISIG
Note: Public keys are sorted in redeem script for deterministic address generation
Spending: Any 2 parties provide 4 signatures total
Address Example: 3FKjZ8rLJXhpBPx8r8ycRd5kq3x7fN2m5T (P2SH)
bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh (P2WSH)
Structure: 2-of-3 via Schnorr MuSig2
βββββββββββββββ βββββββββββββββ βββββββββββββββ
β Party A β β Party B β β Party C β
β (Combined) β β (Combined) β β (Combined) β
βββββββββββββββ βββββββββββββββ βββββββββββββββ
Process:
1. Each party combines Wallet + Key internally (MuSig2)
2. Three combined keys create 2-of-3 threshold Schnorr
3. Spending: Any 2 parties create single aggregated signature
Address Example: bc1p5d7rjq7g6rdk2yhzks9sm5p3rczyr5yz2zkt6qgkq (P2TR)
Structure: 2-of-3 Smart Contract
βββββββββββββββ βββββββββββββββ βββββββββββββββ
β Party A β β Party B β β Party C β
β (Combined) β β (Combined) β β (Combined) β
βββββββββββββββ βββββββββββββββ βββββββββββββββ
Smart Contract Implementation:
contract SSPEnterpriseWallet {
mapping(address => bool) public signers;
uint256 public threshold = 2;
function executeTransaction(
address to,
uint256 value,
bytes memory data,
bytes[] memory signatures
) external {
require(verifySchnorrSignatures(signatures), "Invalid sigs");
require(signatures.length >= threshold, "Insufficient sigs");
// Execute transaction
}
}
Address Example: 0x742d35Cc6671C4e3b8d8B8e9D2f7e2f1A5A5A5A5
SSP Enterprise uses cryptographically separate derivation paths to completely isolate personal and business funds:
Master Seed (Same device, different account numbers)
β
βββ Personal Wallets: m/48'/coin'/account'/script_type'/0/address_index
β βββ Primary Personal: m/48'/0'/0'/2'/0/0 (Bitcoin, account 0)
β βββ Additional Personal: m/48'/0'/1'/2'/0/0 (Bitcoin, account 1)
β βββ Reserved: accounts 0-99 for personal use
β
βββ Business Wallets: m/48'/coin'/account'/script_type'/0/address_index
βββ Company A: m/48'/0'/100'/2'/0/0 (Bitcoin, account 100)
βββ Company B: m/48'/0'/524'/2'/0/0 (Bitcoin, account 524)
βββ Company C: m/48'/0'/7500'/2'/0/0 (Bitcoin, account 7500)
βββ Available: accounts 100-99999 for business use
| Aspect | Personal Keys | Business Keys | Isolation Benefit |
|---|---|---|---|
| Derivation Path | account = 0-99 |
account = 100-99999 |
Cryptographically separate |
| Address Space | Individual control | Multi-party control | Cannot cross-contaminate |
| Transaction History | Private | Business compliance | Clear audit separation |
| Backup/Recovery | Personal seed phrase | Same seed, different account | Unified backup, separate access |
| Tax Reporting | Personal transactions | Business transactions | Automatic categorization |
| Account Selection | Fixed personal accounts | User-chosen 3-digit number | Easy to remember and manage |
// Bitcoin Personal (existing SSP)
const personalPath = "m/48'/0'/0'/2'/0/0"; // account=0 (primary personal)
// Bitcoin Additional Personal
const personalPath2 = "m/48'/0'/15'/2'/0/0"; // account=15 (additional personal)
// Bitcoin Business Accounts (user-chosen 3-digit numbers)
const companyA = "m/48'/0'/100'/2'/0/0"; // account=100 (Company A)
const companyB = "m/48'/0'/524'/2'/0/0"; // account=524 (Company B)
const companyC = "m/48'/0'/7500'/2'/0/0"; // account=7500 (Company C)
// Ethereum Examples
const ethPersonal = "m/48'/60'/0'/0'/0/0"; // Personal Ethereum
const ethBusiness = "m/48'/60'/250'/0'/0/0"; // Business Ethereum (account 250)
// Account Range Summary:
// 0-99: Reserved for personal wallets
// 100-99999: Available for business wallets (user selects memorable unique number)
SSP Enterprise inherits native support for 15+ blockchain networks from the proven SSP Wallet ecosystem:
| Network | Current SSP Support | Enterprise Structure | Key Advantages |
|---|---|---|---|
| Bitcoin | β P2SH, P2WSH | 4-of-6 multisig | Universal compatibility, mature tooling |
| Litecoin | β Native support | 4-of-6 multisig | Fast confirmations, low fees |
| Dogecoin | β Native support | 4-of-6 multisig | High liquidity, community adoption |
| Bitcoin Cash | β Native support | 4-of-6 multisig | Fast transactions, low fees |
| Ravencoin | β Native support | 4-of-6 multisig | Asset tokenization, community-driven |
| Zcash | β Native support | 4-of-6 multisig | Privacy features, shielded transactions |
| Flux | β Native integration | 4-of-6 multisig | Cloud computing blockchain |
| Network | Current SSP Support | Enterprise Structure | Key Advantages |
|---|---|---|---|
| Ethereum | β ERC-4337 Account Abstraction | 2-of-3 smart contract | Gasless transactions, DeFi integration |
| Polygon | β Full support | 2-of-3 smart contract | Ultra-low fees, fast finality |
| BSC | β Full support | 2-of-3 smart contract | High throughput, low cost |
| Base | β Full support | 2-of-3 smart contract | Coinbase backing, L2 efficiency |
| Avalanche | β Full support | 2-of-3 smart contract | Sub-second finality |
Total Supported Networks: 15+ with ongoing expansion
Fireblocks (Custodial MPC)
Trust Model: Company holds 2 of 3 MPC key shares
βββββββββββββββββββ βββββββββββββββββββ βββββββββββββββββββ
β Key Share 1 β β Key Share 2 β β Key Share 3 β
β (Fireblocks) β β (Fireblocks) β β (Customer) β
β Intel SGX β β Intel SGX β β Customer Device β
β AWS Cloud β β Google Cloud β β β
βββββββββββββββββββ βββββββββββββββββββ βββββββββββββββββββ
Assets: 120+ blockchains
Pricing: $100,000-1,000,000+ annually
Reality: NOT self-custody - customer only controls 1/3 of keys
BitGo (Custodial + Self-Custody Options)
Trust Model: Company holds 1 of 3 keys as co-signer
Assets: 1,100+ digital assets supported
Pricing: Enterprise-grade, custom pricing
Features: Regulated custody, insurance up to $250M
Target: Institutional investors, 1,500+ institutions use it
Reality: Hybrid model - still requires trust in BitGo
Safe (formerly Gnosis Safe) - EVM Only
Technology: Smart contract multisig on Ethereum + EVM chains
Assets: Ethereum, USDC, USDT + all ERC-20 tokens, 14 EVM chains
Pricing: Free to use (pay gas fees only)
Users: Manages $100B+ in assets, used by Vitalik Buterin
Limitations: EVM chains only - no Bitcoin, no UTXO chains
Setup: Technical knowledge required, web-based interface
Casa - Hybrid Custody (NOT Full Self-Custody)
Technology: Proprietary service with Casa holding 1 key in multisig
Assets: Bitcoin (primary), Ethereum, USDC, USDT (limited)
Pricing: $250/year (3-key), $2,100/year (5-key premium) + KYC required
Setup: Casa holds 1 key, user holds majority (but not full self-custody)
Target: Individuals comfortable with trusted third party
Limitations: Not open source, Casa dependency, limited multi-chain support
Specter Desktop - Bitcoin Only
Technology: Desktop GUI for Bitcoin Core with hardware wallet support
Assets: Bitcoin ONLY (no multi-chain support)
Pricing: Free and open source
Setup: Requires Bitcoin Core + 1-2TB storage + technical expertise
Target: Bitcoin maximalists and technical users
Limitations: Bitcoin-only, extremely cumbersome setup, 350GB+ storage requirements
Nunchuk - Bitcoin Privacy-Focused
Technology: Bitcoin multisig with privacy focus (no KYC)
Assets: Bitcoin only
Pricing: Subscription model
Setup: Hardware wallet integration (Ledger, Trezor, COLDCARD)
Target: Privacy-conscious Bitcoin users
Limitations: Bitcoin-only, subscription fees, limited business features
TotalSig - Multi-Chain MPC
Technology: MPC technology (not true blockchain multisig)
Assets: Bitcoin, Ethereum, Polygon, Avalanche, BSC, 10+ chains
Pricing: Subscription model
Setup: Software-based MPC solution
Target: Multi-chain users seeking convenience
Limitations: Not true multisig, proprietary technology, subscription cost
| Feature | Fireblocks | BitGo | Safe | Casa | Specter | Nunchuk | TotalSig | SSP Enterprise |
|---|---|---|---|---|---|---|---|---|
| True Self-Custody | β Custodial MPC | β οΈ Hybrid | β Yes | β Casa holds key | β Yes | β Yes | β MPC technology | β Complete |
| Multi-Chain Native | β 120+ chains | β 1,100+ assets | β EVM only | β BTC + limited ETH | β Bitcoin only | β Bitcoin only | β 10+ chains | β 15+ chains |
| Business Features | β Full enterprise | β Institutional | β οΈ Basic DAO tools | β Consumer focus | β None | β None | β οΈ Basic | β Purpose-built |
| Dual-Device Workflow | β οΈ Custom app | β οΈ Enterprise app | β Web only | β Mobile app | β Desktop only | β οΈ Mobile limited | β Mobile app | β Desktop + Mobile |
| Setup Complexity | β οΈ 4-8 weeks | β οΈ Enterprise sales | β οΈ Technical | β οΈ Guided setup | β Very technical | β οΈ Hardware setup | β οΈ Technical | β 1-hour ceremony |
| Annual Cost | $100K-1M+ | $50K-500K+ | $0 (gas only) | $250-2,100 | $0 | Subscription | Subscription | β Free* |
| Blockchain Multisig | β MPC only | β οΈ Hybrid | β Smart contract | β οΈ Hybrid | β Native Bitcoin | β Native Bitcoin | β MPC only | β Native + Smart Contract |
| Security Audited | β οΈ Enterprise only | β οΈ Enterprise only | β Multiple audits | β Proprietary | β οΈ Limited | β Unknown | β Unknown | β Halborn audited |
| Open Source | β Proprietary | β Proprietary | β Core contracts | β Proprietary | β Fully open | β οΈ Partial | β Proprietary | β Full stack |
| Target Market | Large enterprise | Institutions | DeFi/DAOs | Bitcoin users | Bitcoin maximalists | Bitcoin privacy | Multi-chain users | Universal |
| Organization Size | Fireblocks | BitGo | Safe | Casa | Specter | Nunchuk | TotalSig | SSP Enterprise |
|---|---|---|---|---|---|---|---|---|
| Small (3 parties, $1M AUC) | $300,000+ | $150,000+ | $3,000ΒΉ | $750Β² | $0Β³ | $600β΄ | $1,200β΅ | Freeβ· |
| Medium (5 parties, $10M AUC) | $750,000+ | $400,000+ | $15,000ΒΉ | $6,300Β² | $0Β³ | $3,000β΄ | $6,000β΅ | $0-36,000βΆ |
| Large (10 parties, $100M AUC) | $2,000,000+ | $1,200,000+ | $75,000ΒΉ | N/A | $0Β³ | $12,000β΄ | $24,000β΅ | $0-360,000βΆ |
Core Platform: FREE (Open Source)
βββ Multi-party wallet creation and management
βββ Transaction coordination and signing
βββ Basic audit trails and reporting
βββ Cross-chain address generation
βββ Community support
Premium Features: Subscription-Based (AUM-Dependent)
βββ Advanced Analytics & Insights
βββ Enhanced Compliance Reporting
βββ Premium Support & SLA
βββ Advanced Policy Engine
βββ Integration APIs & Webhooks
βββ White-label Customization
Built-in Revenue Features: Transaction-Based
βββ Fiat on-boarding (credit card to crypto)
βββ Fiat off-boarding (crypto to bank account)
βββ Cryptocurrency swapping engine
βββ Competitive rates with enterprise volume discounts
Pricing Tiers:
βββ Starter: $0/month (Core features only)
βββ Professional: 0.3% annually on AUM ($25 minimum)
βββ Enterprise: 0.36% annually on AUM + premium features
βββ Self-Hosted: Free core + premium feature licenses
Pricing Sources & Methodology:
Enterprise Custody Verification:
Transparency Note: Many enterprise providers use "contact sales" pricing, making exact comparisons difficult. Estimates based on publicly available documentation where possible.
β Complete Self-Custody + Multi-Chain
Market Reality:
βββ Fireblocks/BitGo: Multi-chain but custodial (not self-custody)
βββ Safe: Self-custody but EVM-only (no Bitcoin)
βββ Casa: NOT self-custody (Casa holds keys) + limited chains
βββ Specter: Self-custody but Bitcoin-only + extremely technical
βββ Nunchuk: Self-custody but Bitcoin-only + subscription fees
βββ TotalSig: NOT true multisig (MPC) + subscription costs
βββ SSP Enterprise: TRUE self-custody + 15+ chains + Free*
β Blockchain-Level Enforced Multisig + Business Features
Technology Reality:
βββ Fireblocks/BitGo/TotalSig: MPC (not true blockchain multisig)
βββ Safe: True smart contract multisig but EVM-only
βββ Casa: Hybrid approach with trusted third party
βββ Specter/Nunchuk: True Bitcoin multisig but no business features
βββ SSP Enterprise: True multisig (Bitcoin native + EVM smart contracts) + business coordination
β Open Source + Security Audited + Free
Transparency & Cost Reality:
βββ Fireblocks/BitGo/Casa/TotalSig: Proprietary + expensive
βββ Safe: Open source + audited but limited chains
βββ Specter: Open source + free but Bitcoin-only + complex setup
βββ Nunchuk: Partially open + subscription costs
βββ SSP Enterprise: Fully open source + Halborn audited + Free* core platform
β Mobile-Native + Enterprise-Ready
User Experience Reality:
βββ Fireblocks/BitGo: Enterprise complexity, weeks to setup
βββ Safe: Web-only interface, technical setup
βββ Specter: Desktop-only, requires Bitcoin Core + 1-2TB storage
βββ Casa: Mobile but NOT self-custody + limited business features
βββ Nunchuk: Mobile but Bitcoin-only + no business features
βββ SSP Enterprise: Desktop + Mobile coordination + business features + 1-hour setup
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Enterprise Security Stack β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Layer 5: Regulatory & Compliance β
β β’ Immutable blockchain audit trails β
β β’ Multi-jurisdictional compliance support β
β β’ Real-time transaction monitoring β
β β’ Customizable reporting and documentation β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Layer 4: Business Policy Engine β
β β’ Configurable spending limits and approval workflows β
β β’ Role-based access control (Admin, Signer, Observer) β
β β’ Time-based restrictions and emergency procedures β
β β’ Integration with enterprise identity systems β
β β’ Note: UI-enforced policies (true self-custody allows β
β bypassing via custom UI implementations) β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Layer 3: Blockchain Security β
β β’ Native multisig verification (Bitcoin 4-of-6) β
β β’ Smart contract enforcement (EVM 2-of-3) β
β β’ Immutable transaction finality β
β β’ Network consensus validation β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Layer 2: SSP Wallet 2FA (Proven in Production) β
β β’ Dual-device requirement per party β
β β’ BIP48 hierarchical deterministic key derivation β
β β’ Device-specific encryption and authentication β
β β’ Separation of signing and coordination β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Layer 1: Device-Level Protection β
β β’ Operating system security and updates β
β β’ Hardware security module utilization β
β β’ Biometric and PIN-based authentication β
β β’ Secure enclave and keychain integration β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
| Attack Type | Traditional Multisig | Fireblocks MPC | SSP Enterprise | Mitigation Strategy |
|---|---|---|---|---|
| Device Compromise | β οΈ Single point failure | β MPC protection | β Multi-party + 2FA | Requires 2+ parties AND 2FA |
| Insider Threat | β Full access if admin | β οΈ Fireblocks trust | β Threshold enforcement | Cannot act alone |
| Social Engineering | β οΈ Target key holders | β οΈ Target Fireblocks | β Multi-party verification | No single point of control |
| Malware/Phishing | β Can steal keys | β οΈ Can affect shares | β 2FA protection | Mobile confirmation required |
| Physical Coercion | β Force signing | β οΈ Force Fireblocks | β Distributed parties | Geographic distribution |
| Vendor Failure | β No vendor | β Fireblocks bankruptcy | β No vendor dependency | Self-sovereign architecture |
| Regulatory Seizure | β Individual action | β Fireblocks compliance | β Individual responsibility | Cannot be collectively seized |
| Key Loss/Recovery | β οΈ Complex recovery | β οΈ Vendor dependent | β Standard BIP48 | Industry-standard recovery |
While SSP Enterprise's core functionality relies on the proven software-based SSP ecosystem, future hardware integration will provide additional security layers for enterprise deployments.
Current SSP Security Model (Software-Based):
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Proven Security Features β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β
β Device-Level Protection: β
β βββ Mobile biometric authentication (SSP Key) β
β βββ Browser extension secure storage β
β βββ Device-specific encryption keys β
β βββ PIN/password protection layers β
β β
β Cryptographic Security: β
β βββ BIP48 hierarchical deterministic keys β
β βββ AES-GCM encryption with PBKDF2 β
β βββ Device fingerprinting for secondary encryption β
β βββ Zero server-side key storage β
β β
β Audit & Compliance: β
β βββ Halborn security audit passed (March 2025) β
β βββ Enterprise coordination data model β
β βββ Open source transparency β
β βββ Mathematical proof of security model β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Level 1: FIDO2 Authentication Enhancement (Planned 2026)
Current SSP + Hardware Token:
βββ Hardware key authenticates wallet access
βββ Seed phrase remains in secure device storage
βββ Signing operations in SSP Wallet/Key apps
βββ Additional physical security layer
βββ Enterprise compliance improvement
Level 2: Encrypted Seed Storage (Recommended - Target 2027)
Hardware-Encrypted Storage (Sweet Spot):
βββ Seed phrase encrypted and stored on hardware key
βββ PIN/biometric required for seed decryption
βββ Seed temporarily transmitted to SSP Wallet/Key for signing
βββ Memory cleared immediately after transaction
βββ Hardware tamper resistance protects encrypted seed
βββ Signing still occurs in familiar SSP apps
Level 3: Hardware-Only Operations (Future - 2028+)
Pure Hardware Signing (Maximum Security):
βββ Seed never leaves hardware security key
βββ Signing operations performed entirely in hardware
βββ Only public keys and signatures transmitted
βββ Requires custom hardware development
βββ True airgapped security model
βββ May be unnecessary for most enterprise use cases
| Hardware Key | Storage Capacity | Enterprise Features | Cost per Key |
|---|---|---|---|
| YubiKey 5 NFC | 25 encrypted credentials | FIDO2, OpenPGP, PIV | $55 |
| YubiKey 5C Nano | 25 encrypted credentials | USB-C, compact form | $60 |
| YubiKey Bio | 25 + biometric | Fingerprint unlock | $85 |
| Nitrokey 3 | 50+ credentials | Open source firmware | $49 |
| SoloKey | Variable | Open hardware/software | $20-40 |
Scenario 1: Executive Team Security
High-Value Asset Protection:
βββ Each executive: Personal YubiKey Bio
βββ Seed phrases never in device memory
βββ Biometric + PIN dual protection
βββ Hardware audit logs for compliance
βββ Secure backup keys in company vault
Scenario 2: Distributed Team Operations
Multi-Location Security:
βββ Standardized YubiKey deployment
βββ Central hardware key management
βββ Role-based access with different keys
βββ Geographic distribution of backup keys
βββ Remote attestation capabilities
Scenario 3: Regulatory Compliance
Maximum Security Requirements:
βββ Hardware-only signing operations
βββ Air-gapped seed storage
βββ Physical key ceremonies for setup
βββ Multi-party hardware key custody
βββ Immutable hardware audit trails
Seed Storage Process:
βββββββββββββββ βββββββββββββββ βββββββββββββββ
β Seed β β Hardware β β Encrypted β
β Generation βββββΆβ Encryption βββββΆβ Storage β
β (BIP39) β β (YubiKey) β β (Hardware) β
βββββββββββββββ βββββββββββββββ βββββββββββββββ
Transaction Signing Process:
βββββββββββββββ βββββββββββββββ βββββββββββββββ βββββββββββββββ
β Transaction β β Hardware β β In-Hardware β β Signature β
β Request βββββΆβ PIN/Bio βββββΆβ Signing βββββΆβ Return β
β β β Auth β β Operation β β β
βββββββββββββββ βββββββββββββββ βββββββββββββββ βββββββββββββββ
vs. Software-Only Storage:
vs. Traditional Hardware Wallets:
Phase 1: FIDO2 Authentication (Q3 2026)
Phase 2: Encrypted Seed Storage (Q1 2027)
Phase 3: Hardware Signing Operations (Q3 2027)
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β SSP Enterprise Web Portal β
β β
β Step 1: Administrator Initiates Setup β
β βββ Define business requirements β
β βββ Set threshold (2-of-3, 3-of-5, etc.) β
β βββ Configure spending policies β
β βββ Generate secure invitation links β
β β
β Step 2: Party Onboarding β
β βββ Each party connects existing SSP Wallet β
β βββ Platform verifies SSP Key pairing β
β βββ Role assignment (Admin, Signer, Observer) β
β βββ Policy acknowledgment and acceptance β
β β
β Step 3: Cryptographic Setup β
β βββ Coordinate public key exchange β
β βββ Generate multi-chain enterprise addresses β
β βββ Verify address derivation across parties β
β βββ Create initial funding transactions β
β β
β Step 4: Operational Validation β
β βββ Test transaction workflow β
β βββ Verify all parties can sign β
β βββ Confirm policy enforcement β
β βββ Document setup for compliance β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Transaction Lifecycle: Proposal β Approval β Execution
βββββββββββββββ βββββββββββββββ βββββββββββββββ βββββββββββββββ βββββββββββββββ
β Initiator β β Policy β β Required β β Signature β β Blockchain β
β Proposes βββΊβ Engine βββΊβ Parties βββΊβ Collection βββΊβ Execution β
β Transaction β β Evaluation β β Approval β β & Broadcast β β β
βββββββββββββββ βββββββββββββββ βββββββββββββββ βββββββββββββββ βββββββββββββββ
β β β β β
β β βΌ β β
β β βββββββββββββββββββββββ β β
β β β SSP Wallet UI β β β
β β β β’ Review details β β β
β β β β’ Verify recipient β β β
β β β β’ Check policy β β β
β β β β’ Initial approval β β β
β β βββββββββββββββββββββββ β β
β β β β β
β β βΌ β β
β β βββββββββββββββββββββββ β β
β β β SSP Key Mobile β β β
β β β β’ Biometric auth β β β
β β β β’ Transaction hash β β β
β β β β’ Final confirmation β β β
β β βββββββββββββββββββββββ β β
β β β β β
ββββββββββββββββββΌβββββββββββββββββΌβββββββββββββββββΌβββββββββββββββββ
β β β
βββββββββββββββββββββββββββββββββββββββββββββββββββ
β Platform Coordination β
β β’ Collect signatures from required parties β
β β’ Verify threshold requirements are met β
β β’ Validate against business policies β
β β’ Construct final transaction β
β β’ Submit to blockchain network β
β β’ Update audit trail and notify all parties β
βββββββββββββββββββββββββββββββββββββββββββββββββββ
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Policy Configuration β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β
β Spending Limits: β
β βββ Daily/Monthly transaction limits β
β βββ Per-party individual limits β
β βββ Recipient whitelist/blacklist β
β βββ Asset-specific restrictions β
β β
β Approval Workflows: β
β βββ Threshold requirements by amount β
β βββ Required approvers for specific operations β
β βββ Time-based restrictions (business hours) β
β βββ Multi-level approval for large transactions β
β β
β Risk Management: β
β βββ Transaction velocity monitoring β
β βββ Anomaly detection and alerts β
β βββ Compliance screening integration β
β βββ Emergency freeze procedures β
β β
β Audit & Compliance: β
β βββ Immutable transaction logging β
β βββ Role-based access tracking β
β βββ Automated compliance reporting β
β βββ Integration with enterprise systems β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Open Source Foundation (No Cost):
βββ Multi-party wallet setup and management
βββ Transaction coordination and signing
βββ Cross-chain address generation
βββ Basic transaction history and audit trails
βββ Community support and documentation
βββ Self-hosting capability with full source code
βββ Standard compliance reporting
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Premium Analytics Dashboard β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β
β Asset Intelligence: β
β βββ Portfolio composition and diversification β
β βββ Asset performance tracking and ROI analysis β
β βββ Cross-chain yield optimization recommendations β
β βββ DeFi opportunity detection and risk scoring β
β β
β Transaction Analytics: β
β βββ Spending pattern analysis and behavioral insights β
β βββ Counterparty risk assessment and scoring β
β βββ Cost basis tracking and tax optimization β
β βββ Predictive cash flow modeling β
β β
β Compliance Intelligence: β
β βββ Automated regulatory reporting generation β
β βββ AML/KYC risk screening and monitoring β
β βββ Multi-jurisdictional compliance tracking β
β βββ Custom audit reports and documentation β
β β
β Business Intelligence: β
β βββ Multi-party activity correlation analysis β
β βββ Enterprise-grade SLA and support β
β βββ Custom API integrations and webhooks β
β βββ White-label deployment and customization β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Revenue Model Strategy:
βββ Core Platform: Free (drives adoption)
βββ Analytics Premium: 0.3% annually on AUM
βββ Enterprise Features: 0.36% annually on AUM
βββ Professional Services: Custom pricing
βββ White-label Licensing: One-time + revenue share
βββ Self-Hosted Premium: Feature licensing model
Value Proposition:
βββ 10-50x cheaper than custodial alternatives
βββ Transparent pricing based on asset value
βββ No transaction limits or hidden fees
βββ Pay only for premium features you use
βββ Full self-hosting option available
Challenge: Multi-signature approval for company funds without giving up custody
Setup: CEO + CFO + Board Member (2-of-3)
Benefits:
β
No single person can access funds
β
Board oversight on major expenditures
β
Fast mobile approval for routine payments
β
Complete audit trail for compliance
β
Cross-chain treasury management
Example: $50M company treasury
- Daily operations: CEO + CFO approval
- Major investments: CEO + Board Member
- Emergency procedures: Any 2 parties
Challenge: Shared control of partnership funds with clear accountability
Setup: Partner A + Partner B + Neutral Party (2-of-3)
Benefits:
β
Equal control prevents disputes
β
Neutral arbitrator for conflicts
β
Transparent fund management
β
Easy dissolution procedures
Example: Real estate investment partnership
- Property purchases: Both partners agree
- Management expenses: Either partner + neutral
- Profit distribution: Automated smart contracts
Challenge: Client escrow accounts with regulatory compliance
Setup: Lawyer + Client + Trust Account Manager (2-of-3)
Benefits:
β
Client funds protection
β
Regulatory compliance built-in
β
Transparent fee structures
β
Automated trust accounting
Example: Legal escrow for M&A transaction
- Funds release: Lawyer + Client approval
- Fee payment: Any 2 parties
- Compliance reporting: Automatic
Challenge: Decentralized decision making with security
Setup: Multiple fund managers with configurable thresholds
Benefits:
β
Democratic fund management
β
Transparent investment decisions
β
Automated governance integration
β
Institutional-grade security
Example: Crypto investment fund
- Investment decisions: Majority approval
- Routine operations: Simplified threshold
- Emergency procedures: Admin override
Challenge: Multi-generational wealth management with succession planning
Setup: Parents + Adult Children + Family Office Manager
Benefits:
β
Gradual wealth transition
β
Education through participation
β
Professional oversight
β
Estate planning integration
Example: $100M family office
- Conservative investments: Any family member + manager
- Major decisions: Multiple family members
- Next generation: Observer roles transitioning to signers
β Cannot Change After Creation:
βββ Bitcoin: 4-of-6 multisig address is permanent
βββ Ethereum: Smart contract threshold is immutable
βββ Cannot add/remove signers dynamically
βββ Requires new wallet setup for changes
Impact: Less flexible than MPC solutions for growing organizations
Mitigation: Plan threshold carefully during setup
β No Automated Payments:
βββ Every transaction requires human approval
βββ No policy-based automatic execution
βββ Cannot schedule recurring payments
βββ No algorithmic trading support
Impact: Not suitable for high-frequency operations
Mitigation: Focus on treasury and approval workflows
β Technical Constraints:
βββ Bitcoin: Must use 4-of-6 (not 2-of-3) due to ECDSA
βββ Higher transaction fees for complex multisig
βββ Larger transaction sizes on UTXO chains
βββ Smart contract risks on EVM chains
Impact: Higher costs and complexity than simple wallets
Mitigation: Costs still lower than custodial solutions
β Multi-Party Coordination:
βββ All parties must be available for signing
βββ Mobile connectivity required for approval
βββ Time zone coordination for global teams
βββ Potential delays during approval process
Impact: Slower than custodial solutions for urgent transactions
Mitigation: Plan approval workflows and emergency procedures
Better Alternative: Fireblocks
βββ High-frequency trading operations
βββ Algorithmic treasury management
βββ Complex automated payment workflows
βββ Dynamic organizational structures
βββ Reason: Need automation > self-custody
Better Alternative: Safe (Gnosis Safe)
βββ DeFi-focused operations
βββ Ethereum/EVM-only asset portfolios
βββ DAO governance requirements
βββ Web3-native organizations
βββ Reason: Safe is free and purpose-built for EVM
Better Alternative: Casa or Specter Desktop
βββ Bitcoin maximalist organizations
βββ Simple Bitcoin treasury needs
βββ No multi-chain requirements
βββ Preference for Bitcoin-specific tools
βββ Reason: Specialized Bitcoin solutions are simpler
Perfect Fit: No good alternative exists
βββ Bitcoin + Ethereum + other chains
βββ True self-custody requirements
βββ Business approval workflows needed
βββ Mobile-friendly operations preferred
βββ Reason: Only solution combining all requirements
Prioritizing True Ownership: Complete asset control
βββ Organizations requiring genuine asset ownership
βββ Regulatory environments favoring transparency
βββ Privacy-conscious businesses
βββ Institutions mandating direct asset control
βββ Reason: Proven self-custody with business features
Budget Alternative To: Fireblocks/BitGo
βββ Startups with crypto treasuries
βββ SMBs needing multi-party approval
βββ Non-profits managing donations
βββ Partnerships requiring shared control
βββ Reason: 90% cost savings vs enterprise custodial
Building on Proven SSP Infrastructure
π― Core Deliverables:
βββ SSP Enterprise web portal for business coordination
βββ Multi-party address generation (leveraging existing SSP chains)
βββ Transaction proposal and approval workflows
βββ Integration with existing SSP Wallet/Key ecosystem
βββ Business policy engine and spending controls
βββ Compliance audit trails and reporting
π§ Technical Implementation:
βββ Extend SSP Relay server for multi-party coordination
βββ Deploy enterprise smart contracts on supported EVM chains
βββ Implement BIP48 business account derivation paths (accounts 100-99999)
βββ Create enterprise-specific UI components
βββ Policy engine for business rules and approvals
βββ Integration testing across all SSP-supported chains
ποΈ Leveraging Existing SSP Infrastructure:
βββ Reuse SSP Wallet browser extension (no changes needed)
βββ Reuse SSP Key mobile app (minimal UI updates)
βββ Extend SSP Relay for multi-party message coordination
βββ Leverage existing 15+ blockchain network support
βββ Build on proven BIP48 key derivation architecture
βββ Maintain zero-server-key-storage security model
βββ Deliver enterprise security through open source transparency
π Success Metrics:
βββ 10+ pilot organizations successfully onboarded
βββ $1M+ in multi-party enterprise treasury managed
βββ Zero security incidents during deployment
βββ <1 hour average multi-party setup ceremony time
βββ Seamless integration with existing SSP user base
π― Deliverables:
βββ Advanced business policy engine with rules
βββ Spending limits and approval workflow automation
βββ Compliance reporting and audit export tools
βββ Mobile-optimized platform interface
βββ Integration APIs for business systems
βββ Multi-chain expansion (Polygon, BSC, Base)
π§ Technical Milestones:
βββ Policy engine with configurable business rules
βββ RESTful APIs for enterprise system integration
βββ Mobile-responsive web application
βββ Cross-chain transaction coordination
βββ Advanced notification and alerting system
βββ Performance optimization for mobile devices
π Success Metrics:
βββ 100+ organizations using the platform
βββ $10M+ in managed enterprise treasuries
βββ Advanced policy features in production
βββ <5 minute transaction approval times
π― Deliverables:
βββ Bitcoin Taproot 2-of-3 implementation (MuSig2)
βββ YubiKey hardware security integration
βββ Zero-knowledge proof enhancements
βββ Enterprise SSO and identity integration
βββ Advanced fraud detection and monitoring
βββ SOC 2 Type II compliance certification
π§ Technical Milestones:
βββ MuSig2 implementation for Bitcoin Taproot
βββ FIDO2/WebAuthn integration with YubiKey
βββ SAML/OIDC integration for enterprise identity
βββ Machine learning fraud detection models
βββ Security audit and certification processes
βββ White-label deployment capabilities
π Success Metrics:
βββ 500+ organizations on platform
βββ $100M+ in managed treasuries
βββ SOC 2 Type II certification achieved
βββ Zero successful attacks or breaches
π― Deliverables:
βββ Multi-chain expansion (Solana, Cosmos, Cardano)
βββ DeFi protocol integrations and yield strategies
βββ Institutional custody partnerships
βββ White-label solutions for financial institutions
βββ Advanced analytics and business intelligence
βββ Global regulatory compliance automation
π§ Technical Milestones:
βββ Universal multi-chain architecture
βββ DeFi protocol abstraction layer
βββ Institutional-grade analytics dashboard
βββ White-label deployment framework
βββ Global compliance automation engine
βββ Enterprise marketplace integrations
π Success Metrics:
βββ 1,000+ organizations ecosystem-wide
βββ $1B+ in managed digital assets
βββ Multiple regulatory certifications
βββ Profitable recurring revenue model
Market Reality Map:
Multi-Chain Support
β
β
Fireblocks/BitGo β No Solution Exists
(Custodial) β (Market Gap)
β’ Multi-chain β
β’ Enterprise features β
β’ NOT self-custody β
β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Custodial β Self-Custody
β
Not Applicable β Safe, Casa, Specter
(No self-custody) β (Self-custody)
β β’ Single chain focus
β β’ Limited business features
Single Chain Focus
Market Gap Identified: No solution exists for multi-chain business self-custody
When to choose SSP Enterprise over Fireblocks:
β
Self-custody is non-negotiable
β
Transparency and auditability required
β
Cost reduction is priority (90% savings)
β
No vendor lock-in desired
When to choose Fireblocks over SSP Enterprise:
β
Automation and policy engines needed
β
Dynamic threshold changes required
β
High-frequency operations
β
Willing to trade custody for convenience
When to choose SSP Enterprise over Safe:
β
Need Bitcoin or other non-EVM chains
β
Traditional business features required
β
Mobile-native workflow preferred
β
Unified multi-chain management
When to choose Safe over SSP Enterprise:
β
EVM-only asset portfolio
β
DeFi-focused operations
β
DAO governance needs
β
Free solution acceptable (gas fees only)
When to choose SSP Enterprise over Casa/Specter:
β
Multi-chain asset portfolio
β
Business coordination features needed
β
Mobile workflow preferred
β
Enterprise-grade audit trails
When to choose Casa/Specter over SSP Enterprise:
β
Bitcoin-only holdings
β
Simpler setup preferred
β
Lower annual costs acceptable
β
Bitcoin-maximalist philosophy
Market Size: Currently underserved/non-existent
Characteristics:
βββ $100K - $100M digital asset portfolios
βββ Bitcoin + Ethereum + other chains
βββ 2-10 stakeholders requiring approval
βββ Self-custody mandate (regulatory or philosophical)
βββ Business approval workflows needed
βββ Mobile-preferred operational style
Examples:
βββ Crypto startups with diverse portfolios
βββ Investment DAOs with multi-chain strategies
βββ Family offices with cross-chain holdings
βββ Partnerships managing diverse crypto assets
βββ SMBs accepting multiple cryptocurrencies
Market Size: Large, price-sensitive segment
Characteristics:
βββ Currently using expensive custodial solutions
βββ Seeking cost reduction without losing features
βββ Willing to trade some automation for savings
βββ Self-custody becoming regulatory requirement
βββ Multi-signature governance already established
Examples:
βββ Mid-market companies reducing crypto costs
βββ Non-profits managing donor cryptocurrencies
βββ Professional services with shared crypto accounts
βββ International businesses prioritizing direct asset control
βββ Regulated entities requiring transparency
Participants: 2-10 parties per enterprise wallet
Each party needs:
βββ Existing SSP Wallet (Chrome/Firefox extension)
βββ Existing SSP Key (iOS/Android mobile app)
βββ Modern web browser (Chrome/Firefox/Safari/Edge)
βββ Reliable internet connectivity for coordination
βββ Basic cryptocurrency knowledge
Setup Time: ~1 hour for initial ceremony
Ongoing: ~5 minutes per transaction approval
Roles & Responsibilities:
βββ Administrator: Wallet setup and policy management
βββ Signers: Transaction approval authority
βββ Observers: Read-only access to transactions
βββ IT Support: Technical assistance and troubleshooting
Documentation:
βββ Business continuity procedures
βββ Key backup and recovery processes
βββ Emergency access protocols
βββ Compliance and audit procedures
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β SSP Enterprise Architecture β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Frontend: React/TypeScript SPA β
β Backend: Node.js/Express API server β
β Database: MongoDB for coordination and audit β
β Blockchain: Smart contracts on target networks β
β Security: End-to-end encryption, zero-knowledge proofs β
β Integration: WalletConnect, enterprise SSO β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
SSP Wallet Extensions:
// Business account derivation (user-chosen 3-digit numbers)
const BUSINESS_ACCOUNT_MIN = 100;
const BUSINESS_ACCOUNT_MAX = 99999;
function validateBusinessAccount(account: number): boolean {
return account >= BUSINESS_ACCOUNT_MIN && account <= BUSINESS_ACCOUNT_MAX;
}
// Business wallet derivation path
const businessPath = `m/48'/${coin}'/${businessAccount}'/${scriptType}'/0/${addressIndex}`;
// Enterprise transaction handling
interface EnterpriseTransaction {
type: 'enterprise';
businessAccount: number; // 100-99999
walletId: string;
threshold: number;
parties: PartyInfo[];
policy: BusinessPolicy;
approvals: ApprovalStatus[];
}
// Multi-party address generation
export function generateEnterpriseAddress(
partyPubkeys: Buffer[],
threshold: number,
businessAccount: number,
chain: keyof cryptos
): EnterpriseAddress;
SSP Key Extensions:
// Enterprise signing context
interface EnterpriseSigningRequest {
transactionId: string;
businessContext: {
walletName: string;
policy: BusinessPolicy;
currentApprovers: string[];
amount: string;
recipient: string;
purpose: string;
};
technicalContext: {
inputs: UTXO[];
outputs: Output[];
fee: string;
chainId: number;
};
}
// Enhanced approval flow
export function approveEnterpriseTransaction(
request: EnterpriseSigningRequest,
biometricAuth: boolean
): Promise<PartialSignature>;
SSP Relay Extensions:
// Multi-party coordination service
class EnterpriseCoordinator {
async createWallet(
parties: Party[],
threshold: number,
policies: BusinessPolicy[]
): Promise<EnterpriseWallet>;
async proposeTransaction(
walletId: string,
transaction: Transaction,
proposer: string
): Promise<TransactionProposal>;
async collectApprovals(
proposalId: string
): Promise<ApprovalCollection>;
async executeTransaction(
proposalId: string
): Promise<TransactionResult>;
}
Smart Contract Infrastructure:
SSP Enterprise leverages the proven, open-source smart contract
infrastructure and SDK already developed and security-audited by the SSP
team:
SSP Enterprise represents a fundamental shift from "trust us" to "verify everything":
Traditional Approach: Trust the Institution
βββ Rely on company promises
βββ Accept proprietary "black box" security
βββ Depend on institutional controls
βββ Hope for business continuity
SSP Enterprise Approach: Verify Everything
βββ Cryptographic proof of security
βββ Open source transparency
βββ Direct blockchain verification
βββ Self-sovereign control
Problem 1: Custody vs Control Trade-off
Problem 2: Transparency vs Functionality
Problem 3: Multi-Chain vs Simplicity
Problem 4: Cost vs Quality
The Freemium Advantage:
Sustainable Value Creation:
Traditional Model Problems:
βββ High upfront costs block adoption
βββ Transaction fees punish usage
βββ Vendor lock-in prevents switching
βββ Proprietary systems hide costs
βββ Fixed pricing ignores value delivered
SSP Enterprise Solution:
βββ Free adoption removes barriers
βββ No transaction limits encourage usage
βββ Open source prevents lock-in
βββ Transparent pricing builds trust
βββ Value-based fees align incentives
SSP Enterprise represents the natural evolution of the proven SSP Wallet ecosystem into enterprise multi-party coordination.
Rather than building entirely new infrastructure, SSP Enterprise intelligently extends the battle-tested SSP architecture that's already securing user funds across 15+ blockchain networks. This approach delivers enterprise features while maintaining the security, simplicity, and cost-effectiveness that made SSP Wallet successful.
SSP Enterprise fills a unique gap: multi-chain business self-custody. While Fireblocks offers automation at the cost of custody, and Safe provides EVM-only self-custody, SSP Enterprise delivers true multi-chain self-custody with business coordination features.
For organizations requiring multi-chain asset management with true self-custody principles, SSP Enterprise isn't just competitive β it's the only complete solution available.
Ready to take control of your business cryptocurrency management with true self-custody?
SSP Enterprise: Where security meets simplicity, and ownership meets enterprise.
Built on the proven foundation of the SSP Wallet ecosystem, SSP Enterprise delivers institutional-grade multi-party custody without sacrificing the self-sovereignty principles that make cryptocurrency transformative.