Architecture

Non-custodial by construction.

Your keys. Your assets. Our infrastructure. Lux Financial is the first regulated bank where plaintext custody of client funds is mathematically impossible — the bank physically cannot move your money alone.

Four Principles

Why non-custodial is the only honest answer after FTX, Celsius, BlockFi, and Voyager.

Keys Never Leave the User

Signing keys are generated on the user device or split across MPC parties. The bank sees ciphertext and signatures — never seed phrases, never plaintext private keys.

Bank as Coordinator, Not Custodian

Lux routes orders, proves compliance, and records settlement. The user's self-custodied key (or MPC share) is the only thing that can actually move funds.

You Can Walk Away

Users export keys, rotate MPC cohorts, or migrate to another wallet at any time. No vendor lock-in. No frozen balances if we disappear.

Regulated Without Rehypothecation

Broker-dealer rails, SEC/FINRA reporting, and Travel Rule attestations — all achieved without the platform ever holding plaintext custody of client assets.

The signing path.

Every state-changing action on Lux Financial — transfers, trades, withdrawals, governance votes — follows the same path: user intent, threshold signing across the MPC cohort, HSM-attested policy check, and public ledger settlement.

User device generates an MPC share at onboarding — never exported
Recovery share is split across 16 independent custodians using Shamir secret sharing
Any 16-of-N threshold can recover — no single recovery service can steal keys
Compliance policy is a precondition, not a post-hoc override — no admin key
User Device (Share 1)
↓
MPC Node A
MPC Node B
HSM Share
↓ Threshold signature
Z-Chain / A-Chain / Ethereum

The Four Layers

Where your key material lives — and where it does not.

User Device

Secure enclave (iOS Secure Enclave, Android StrongBox, TPM, or YubiKey) holds MPC share #1. Biometric or PIN unlock. Never syncs to the cloud.

MPC Cohort

2-of-3 or 3-of-5 CGGMP21 threshold signing. Shares distributed across independent regions + organizational boundaries. No single party can sign alone.

HSM Root

FIPS 140-2 Level 3 HSM holds the deterministic backup share, policy keys, and audit attestation keys. Tamper-evident, geographically replicated.

Chain

Final signature broadcast to Lux Z-Chain / A-Chain / Ethereum. Settlement is on a public ledger — not in our database.

Custodial vs Non-Custodial

The difference isn't marketing — it's mathematics.

QuestionTraditional custodian → Lux Financial
Who controls keys?The bank (pooled)→User + MPC cohort (threshold)
What does the platform see?Plaintext balances + addresses→FHE ciphertexts + ZK attestations
What happens if we go down?Funds frozen→User signs with backup share + recovers
Proof of reserves?Trust the auditor→On-chain, continuously
Can we freeze your account?Yes→No — only sanctions screening gates routing
Rehypothecation?Often (FTX)→Impossible by construction

What this unlocks

Non-custodial isn't just safer — it's what lets us ship things legacy banks can't.

Your keys. Our infrastructure.

Ship a regulated bank in weeks — without asking users to trust you with their funds.