Layer 1: Transaction Request
- Raw tx
- Safe tx
- Squads tx
- Fireblocks callback
- HSM/MPC request
- Internal signer request
The runtime provenance-gated control plane, integration options, audit evidence, and how a pilot begins.
SignTrail combines transaction payload, runtime provenance, signer identity, and policy context into one signing authorization decision.
External signer (HSM/MPC/Fireblocks/Safe/Squads/internal) that SignTrail sits in front of — not a SignTrail layer.
No replacement. No migration. Add a pre-sign gate to the workflow you already use.
SignTrail records why a request was allowed, held, or rejected.
hash-chained · tamper-evident · signed by collector
prev 7b3e…a4 · runtime_provenance_digest
sha256 9f2a…c1
prev 2c9d…88 · runtime_provenance_digest
sha256 7b3e…a4
prev 4e10…d3 · runtime_provenance_digest
sha256 2c9d…88
prev a731…19 · runtime_provenance_digest
sha256 4e10…d3
prev 46e1…e6 · runtime_provenance_digest
sha256 a731…19
Audit evidence is not an afterthought. It is part of the signing decision.
A SignTrail pilot can begin in shadow mode without interrupting production operations.
observe, no block
Start in shadow mode. Enforce only when the customer is ready.