console

Why we'll never hold your keys

Dami Adeyemi

Security Architect

·

·

5 min read

Holding user keys can make a demo feel smoother, but it changes the business you are in. Suddenly the infrastructure company is also a custodian, an attack target, and a point of failure in the value path.

Hexiora is designed around a different boundary. We help route, sponsor, observe, and recover transactions, but signing authority stays with the user, the wallet, or the system the customer explicitly controls.

Custody is not convenience

The moment a platform can move funds on behalf of a user, every operational mistake becomes existential. Access controls, insider risk, compliance posture, and breach response all become part of the product whether the team wanted them or not.

“The safest key in our system is the one we never receive.”

A cleaner responsibility line

By staying out of custody, Hexiora can focus on the infrastructure layer: request integrity, route selection, policy enforcement, traces, and recovery. Customers keep control over signing, while still getting the operational benefits around the transaction path.

// execution without custody
await hexiora.execute({
  unsignedIntent,
  signer: userWallet,
  policy: customerPolicy,
});
What we still protect

Non-custodial does not mean passive. We still validate request shape, enforce route policy, monitor provider behavior, and return audit-ready traces. We just do it without becoming the actor that can spend user assets.

  • Signing authority stays outside Hexiora.

  • Policy and routing remain fully observable.

  • Security improves when the value path has fewer holders.

We would rather make non-custodial infrastructure feel fast and reliable than make custodial shortcuts look convenient. That boundary is a product decision, not a footnote.

Holding user keys can make a demo feel smoother, but it changes the business you are in. Suddenly the infrastructure company is also a custodian, an attack target, and a point of failure in the value path.

Hexiora is designed around a different boundary. We help route, sponsor, observe, and recover transactions, but signing authority stays with the user, the wallet, or the system the customer explicitly controls.

Custody is not convenience

The moment a platform can move funds on behalf of a user, every operational mistake becomes existential. Access controls, insider risk, compliance posture, and breach response all become part of the product whether the team wanted them or not.

“The safest key in our system is the one we never receive.”

A cleaner responsibility line

By staying out of custody, Hexiora can focus on the infrastructure layer: request integrity, route selection, policy enforcement, traces, and recovery. Customers keep control over signing, while still getting the operational benefits around the transaction path.

// execution without custody
await hexiora.execute({
  unsignedIntent,
  signer: userWallet,
  policy: customerPolicy,
});
What we still protect

Non-custodial does not mean passive. We still validate request shape, enforce route policy, monitor provider behavior, and return audit-ready traces. We just do it without becoming the actor that can spend user assets.

  • Signing authority stays outside Hexiora.

  • Policy and routing remain fully observable.

  • Security improves when the value path has fewer holders.

We would rather make non-custodial infrastructure feel fast and reliable than make custodial shortcuts look convenient. That boundary is a product decision, not a footnote.

Holding user keys can make a demo feel smoother, but it changes the business you are in. Suddenly the infrastructure company is also a custodian, an attack target, and a point of failure in the value path.

Hexiora is designed around a different boundary. We help route, sponsor, observe, and recover transactions, but signing authority stays with the user, the wallet, or the system the customer explicitly controls.

Custody is not convenience

The moment a platform can move funds on behalf of a user, every operational mistake becomes existential. Access controls, insider risk, compliance posture, and breach response all become part of the product whether the team wanted them or not.

“The safest key in our system is the one we never receive.”

A cleaner responsibility line

By staying out of custody, Hexiora can focus on the infrastructure layer: request integrity, route selection, policy enforcement, traces, and recovery. Customers keep control over signing, while still getting the operational benefits around the transaction path.

// execution without custody
await hexiora.execute({
  unsignedIntent,
  signer: userWallet,
  policy: customerPolicy,
});
What we still protect

Non-custodial does not mean passive. We still validate request shape, enforce route policy, monitor provider behavior, and return audit-ready traces. We just do it without becoming the actor that can spend user assets.

  • Signing authority stays outside Hexiora.

  • Policy and routing remain fully observable.

  • Security improves when the value path has fewer holders.

We would rather make non-custodial infrastructure feel fast and reliable than make custodial shortcuts look convenient. That boundary is a product decision, not a footnote.

Content

Build on rails that don't break.

Start free and connect your first chain in minutes — no card required, no sales calls, just a simple way to get started and build with confidence.

Content

Build on rails that don't break.

Start free and connect your first chain in minutes — no card required, no sales calls, just a simple way to get started and build with confidence.

Content

Build on rails that don't break.

Start free and connect your first chain in minutes — no card required, no sales calls, just a simple way to get started and build with confidence.

Create a free website with Framer, the website builder loved by startups, designers and agencies.