Skip to content
ORBITRAONE

Security

Security that evolves.

ORBITRA ONE™ separates keys, duties, runtimes and failure domains across five layers of defense. Q-Switch keeps the cryptography itself replaceable, so protection can move forward as standards, libraries and hardware mature.

Illustration: Signature suites are versioned. An account moves from a classical suite to a hybrid credential that combines classical and post-quantum-ready signatures, rotates its keys and migrates its address without losing its history or assets.

Suite v1 · classical

Suite v2 · hybrid

Suite v3 · post-quantum ready

  1. 01Versioned suites
  2. 02Hybrid credentials
  3. 03Key rotation
  4. 04Address migration
  • Five security layers
  • MPC and HSM signing
  • Signed releases
  • Post-quantum-ready interfaces

Architecture

Every layer assumes another can fail.

Each layer contains a different class of failure. None of them depends on another being perfect.

Illustration: Five concentric security layers — asset, protocol, application, market and operational security — surround the network, with Q-Switch drawn as a ring that spans all of them to show cryptographic agility across every layer.
  1. Asset securityMPC/HSM policies, delayed withdrawals, allowlists
  2. Protocol securityFormal specifications, client diversity, slashing
  3. Application securitySandboxing, capabilities, upgrade controls
  4. Market securitySurveillance, circuit breakers, oracle confidence
  5. Operational securityZero trust, segregation, signed releases
  6. Q-Switch · cryptographic agility across every layer

The illustration shows the five security layers of ORBITRA ONE™ — asset, protocol, application, market and operational security — each labeled with its principal controls, with Q-Switch beneath them as the cryptographic-agility layer that lets signature suites and keys change without disturbing the layers above.

Controls by layer

Five layers and an agile core.

Asset security

Custody governed by policy

MPC and HSM signing policies decide who can authorize a movement of assets. Delayed withdrawals and destination allowlists decide when and where it can go.

Protocol security

Specified and accountable

Formal specifications define consensus and market modules, client diversity limits correlated failure, and slashing makes provable validator misbehavior costly.

Application security

Sandboxed by capability

NexusWASM contracts run metered, with declared capabilities. The EVM Capsule sits behind governed gateways. Upgrades follow explicit controls.

Market security

Surveillance and circuit breakers

Surveillance, price bands and volatility pauses protect order books, and Prism confidence thresholds halt markets when reference data becomes unreliable.

Operational security

Zero trust and segregation

Every internal request is authenticated and authorized, production environments are segregated by function, and only signed builds reach production.

Q-Switch

Cryptographic agility

Versioned signature suites, hybrid credentials, key rotation and address migration prepare every layer for post-quantum standards without a disruptive cutover.

Key and access principles

Six rules for keys and access.

  1. 01

    Separate keys and duties

    No single person, service or key can move assets, change code and approve its own action. Signing, approval and operation are distinct roles.

  2. 02

    Threshold and hardware signing

    High-value keys are held in HSMs or split across MPC participants, so a signature requires policy and quorum, not possession of one secret.

  3. 03

    Least privilege

    Credentials carry only the permissions a task needs, for as long as it needs them. Standing administrative access is the exception.

  4. 04

    Zero trust

    Network location grants nothing. Requests between people, services and machines are authenticated, authorized and logged.

  5. 05

    Signed releases

    Node clients, services and SDK artifacts are signed at build time and verified before they run, so tampered software is rejected rather than discovered later.

  6. 06

    Withdrawal governance

    Delays, allowlists and approval rules apply to assets leaving delegated custody, creating time to detect and stop an unauthorized transfer.

Failure control

When something fails, it fails contained.

Security includes what happens after a control is tested. Every layer has a defined path from detection to recovery.

  1. 01

    Detect

    Market surveillance, protocol monitoring and operational telemetry flag anomalies, from abnormal order flow to divergent state roots.

  2. 02

    Contain

    Circuit breakers pause affected markets, gateway caps limit exposure and permissions can be revoked in a single step.

  3. 03

    Recover

    Deterministic recovery paths — partial liquidation, the insurance waterfall, pause and dispute procedures — restore a consistent state.

  4. 04

    Disclose

    Findings are shared with affected parties, and vulnerabilities are disclosed in coordination with the researchers who reported them.

Suspected vulnerabilities are reported privately through responsible disclosure.

Found a weakness? Tell us first.

Report vulnerabilities privately to hello@orbitraone.com or through the secure form. We confirm, remediate and coordinate disclosure with the people who find them.