Security is the substrate.
Zero-trust architecture with layered transaction controls and key isolation across the signing path.
Built into the signing path.
Every transaction is gated
Each signing request passes authentication, access controls, payload decoding and policy evaluation before a signature can exist.
Keys remain isolated
Key material is generated and used only inside client-controlled, hardware-isolated enclaves. It never leaves the enclave and is never exposed to Fortkey operators.
Defense in depth
Tamper-Proof Enclaves
AWS Nitro Enclaves isolate key operations in a secure environment.
Layered KMS Encryption
Multi-layered KMS ensures not even admins can bypass access to private keys.
Configurable Policies
Define user permissions, transaction limits, and address book checks.
Attested Communications
mTLS enforces encrypted communication everywhere.
International Standards
ISO 27001:2022 certified by Insight Assurance.
Best Dev Practices
Strict CI/CD processes, 4-eyes principle, secure code quality.
Independently verified

ISO 27001:2022
Insight Assurance
Certified
Pen-Test
Cognisys
Completed
Pen-Test
Fox-IT
Completed
Pen-Test
Cyber Cloud
CompletedPen-Test
Aikido
CompletedAuditable, replaceable, and yours.
ISO/IEC 27001 certified
Independently audited information security management. Certificate available on request.
Visit Trust CenterNo vendor lock-in
Customer controls keys, policy, and audit. The runtime is operationally independent of Fortkey, testable in your own disaster-recovery drills, not promised in a brochure.
Runs next to your custodian
Your custodian keeps the treasury. Fortkey is the trading wallet that runs alongside it, with keys generated fresh in your own enclaves.
Review our full security posture
Our Vanta Trust Center provides real-time visibility into Fortkey's security controls, certifications, and audit evidence, verified by a third party.
Hosted and verified by Vanta
Have security questions?
Or email info@fortkey.io