Security architecture

Trust is not a permission model.

Cairnvector separates identity, policy, signing, and operations so no single request—or system—can decide too much.

Layered control

Designed around independent decisions.

Institutional custody is safest when responsibilities remain explicit. Cairnvector makes each boundary visible and enforceable.

Identity boundary

Client identity and portal authorization are established outside conversational and operational workflows.

Policy boundary

Quorum, limits, destinations, and delays are evaluated independently of the person requesting action.

Custody boundary

Vault scope and signing authority remain separate from support, reporting, and integration services.

Evidence boundary

Requests, decisions, cases, and settlement events form one traceable operational record.

3 of 5Standard signer quorum
30 minPolicy delay window
24/7Operator availability
0Transfers approved by support