SignTrail

DPRK-focused Pre-Sign Security Layer

01

Stop Unsafe Signatures Before Assets Move

SignTrail verifies transaction intent, execution path, signer authority, and policy context before digital assets move.

pre-sign layer

SignTrail Gate

verified

request snapshot

$620.58

tx_payload_hash

ALLOWHOLDREJECT
execution path
  1. 01Request
  2. 02Approval
  3. 03SignTrail Gate
  4. 04Signature
  5. 05Asset Movement

Protect the path to signing — not just the key.

Protection Points

SignTrail checks three points before signing

Without replacing your wallet, SignTrail sits in front of the signing workflow you already operate and verifies request, path, and authority.

Why Now

03

Attackers Do Not Just Steal Keys

Even valid signers and trusted systems can approve dangerous transactions when the path is manipulated.

Past Attacks

  • Private key theft
  • Phishing
  • Malware
  • Direct intrusion

New Attacks

  • Valid approver
  • Manipulated signing request
  • Fake UI
  • Compromised developer environment
  • Valid signature
  • Asset theft
01 / 03
evidence

Bybit
$1.5B Incident

A large asset movement that looked approved still led to catastrophic loss.

A hooded operator at a multi-monitor console showing log and threat dashboards.

Source: FBI / IC3 Public Service Announcement on the Bybit incident (TraderTraitor).

request

Transaction Request

pre-sign gate

SignTrail Gate

ALLOWHOLDREJECT

existing signers

HSMMPCFireblocksSafeSquadsInternal Signer

final state

Signature

key position

Verified before keys are used, outside the wallet.

Product Identity

04

SignTrail Does Not
Replace Wallets

SignTrail sits in front of HSM, MPC, Fireblocks, Safe, Squads, and internal signers to verify path and intent.

  • No Replacement
  • Pre-Sign Gate
  • Runtime Provenance
  • Transaction Intent
  • Signer-Side Enforcement
  • Fail-Closed

We are not a company that stores keys. We verify the path right before keys are used.

Customers

05

Who Needs SignTrail?

Teams moving assets or executing privileged onchain operations all carry signing risk.

01

Exchanges

Independent verification before withdrawals and wallet moves.

Exchange Security Review
pre-sign workflow
01withdrawal
02wallet movement
03treasury sweep

How It Works

06

The request, path, and signer must all pass before a transaction is signed.

Before Signing,
Three Checks Must Pass

No trusted path, no signature.

  1. Q1

    Is the request unchanged?

    • Canonical payload
    • tx_payload_hash
    • Integrity
  2. Q2

    Can the path be trusted?

    • Runtime window
    • Process chain
    • File/network
    • provenance_digest
  3. Q3

    May the signer execute?

    • signer_id
    • policy_hash
    • Decision artifact
    • Replay/TTL validation

Product Proof

Record the decision and evidence

SignTrail evaluates intent and execution path, then records the reason before the signer runs.

Decision Stream

Untrusted origin and sensitive file access surface as decision reasons inside normal traffic.

decision p50
63.9μs
combined path
119.4μs
throughput
9,000/s

Stop Hacks Right Before Signing

SignTrail helps exchanges, custodians, DeFi protocols, and treasury teams stop unsafe signing requests before assets move.

The safest signature is the one that never gets executed when the path is wrong.

  • Protect the path to signing
  • Verify transaction intent
  • Detect manipulated runtime paths
  • Hold risky requests
  • Reject unsafe signatures
  • Leave audit evidence