Custody governed by policy
MPC and HSM signing policies decide who can authorize a movement of assets. Delayed withdrawals and destination allowlists decide when and where it can go.
Security
ORBITRA ONE™ separates keys, duties, runtimes and failure domains across five layers of defense. Q-Switch keeps the cryptography itself replaceable, so protection can move forward as standards, libraries and hardware mature.
Suite v1 · classical
Suite v2 · hybrid
Suite v3 · post-quantum ready
Architecture
Each layer contains a different class of failure. None of them depends on another being perfect.
The illustration shows the five security layers of ORBITRA ONE™ — asset, protocol, application, market and operational security — each labeled with its principal controls, with Q-Switch beneath them as the cryptographic-agility layer that lets signature suites and keys change without disturbing the layers above.
Controls by layer
MPC and HSM signing policies decide who can authorize a movement of assets. Delayed withdrawals and destination allowlists decide when and where it can go.
Formal specifications define consensus and market modules, client diversity limits correlated failure, and slashing makes provable validator misbehavior costly.
NexusWASM contracts run metered, with declared capabilities. The EVM Capsule sits behind governed gateways. Upgrades follow explicit controls.
Surveillance, price bands and volatility pauses protect order books, and Prism confidence thresholds halt markets when reference data becomes unreliable.
Every internal request is authenticated and authorized, production environments are segregated by function, and only signed builds reach production.
Versioned signature suites, hybrid credentials, key rotation and address migration prepare every layer for post-quantum standards without a disruptive cutover.
Key and access principles
No single person, service or key can move assets, change code and approve its own action. Signing, approval and operation are distinct roles.
High-value keys are held in HSMs or split across MPC participants, so a signature requires policy and quorum, not possession of one secret.
Credentials carry only the permissions a task needs, for as long as it needs them. Standing administrative access is the exception.
Network location grants nothing. Requests between people, services and machines are authenticated, authorized and logged.
Node clients, services and SDK artifacts are signed at build time and verified before they run, so tampered software is rejected rather than discovered later.
Delays, allowlists and approval rules apply to assets leaving delegated custody, creating time to detect and stop an unauthorized transfer.
Failure control
Security includes what happens after a control is tested. Every layer has a defined path from detection to recovery.
Market surveillance, protocol monitoring and operational telemetry flag anomalies, from abnormal order flow to divergent state roots.
Circuit breakers pause affected markets, gateway caps limit exposure and permissions can be revoked in a single step.
Deterministic recovery paths — partial liquidation, the insurance waterfall, pause and dispute procedures — restore a consistent state.
Findings are shared with affected parties, and vulnerabilities are disclosed in coordination with the researchers who reported them.
Suspected vulnerabilities are reported privately through responsible disclosure.
Report vulnerabilities privately to hello@orbitraone.com or through the secure form. We confirm, remediate and coordinate disclosure with the people who find them.