Four Principles
Why non-custodial is the only honest answer after FTX, Celsius, BlockFi, and Voyager.
Keys Never Leave the User
Signing keys are generated on the user device or split across MPC parties. The bank sees ciphertext and signatures — never seed phrases, never plaintext private keys.
Bank as Coordinator, Not Custodian
Lux routes orders, proves compliance, and records settlement. The user's self-custodied key (or MPC share) is the only thing that can actually move funds.
You Can Walk Away
Users export keys, rotate MPC cohorts, or migrate to another wallet at any time. No vendor lock-in. No frozen balances if we disappear.
Regulated Without Rehypothecation
Broker-dealer rails, SEC/FINRA reporting, and Travel Rule attestations — all achieved without the platform ever holding plaintext custody of client assets.
The signing path.
Every state-changing action on Lux Financial — transfers, trades, withdrawals, governance votes — follows the same path: user intent, threshold signing across the MPC cohort, HSM-attested policy check, and public ledger settlement.
The Four Layers
Where your key material lives — and where it does not.
User Device
Secure enclave (iOS Secure Enclave, Android StrongBox, TPM, or YubiKey) holds MPC share #1. Biometric or PIN unlock. Never syncs to the cloud.
MPC Cohort
2-of-3 or 3-of-5 CGGMP21 threshold signing. Shares distributed across independent regions + organizational boundaries. No single party can sign alone.
HSM Root
FIPS 140-2 Level 3 HSM holds the deterministic backup share, policy keys, and audit attestation keys. Tamper-evident, geographically replicated.
Chain
Final signature broadcast to Lux Z-Chain / A-Chain / Ethereum. Settlement is on a public ledger — not in our database.
Custodial vs Non-Custodial
The difference isn't marketing — it's mathematics.
What this unlocks
Non-custodial isn't just safer — it's what lets us ship things legacy banks can't.
MPC signing
CGGMP21 threshold ECDSA and Corona threshold ML-DSA. 2-of-3, 3-of-5, or 16-of-N cohorts.
KMS & HSM
Per-tenant isolation, HSM-backed root of trust, FIPS 140-2 Level 3 modules.
ZAP attestations
Prove solvency, eligibility, and compliance without ever revealing positions.
FHE execution
CKKS-encrypted orders — the matching engine itself never sees plaintext.
Compliance without custody
Travel Rule, OFAC, Reg ATS — satisfied via ZK proofs, not by controlling your keys.
Proof of reserves
Continuous on-chain attestation. No quarterly PDFs. No CEX-style blackbox.
Your keys. Our infrastructure.
Ship a regulated bank in weeks — without asking users to trust you with their funds.