Skip to content
ORTHEON
SYSTEMS LABORATORY
Assessment archive

Institutional Asset Custody / Assessment case

Obsidian Custody

Additional controls implemented

01 / System overview

A policy-governed custody environment separating transaction intent, approval and cryptographic execution.

The assessment resulted in additional approval boundaries and automated withdrawal controls.

02 / Architecture diagram

N1Request Portal
N2Policy Engine
N3Approval Quorum
N4Signing Enclave
N5Settlement Vault

03 / Assessment scope

Multisignature policies
Approval workflows
Key generation
Transaction limits
Disaster recovery

04 / Threat model

T-01

Approval collusion

T-02

Policy bypass

T-03

Key ceremony failure

T-04

Unbounded transaction

05 / Findings by severity

High0

No critical asset-loss path was reproduced.

Medium4

Approval separation and transaction-limit enforcement.

Low3

Recovery evidence and policy observability.

06 / Remediation timeline

Phase 01Authority and policy mapping
Phase 02Workflow abuse and recovery simulation
Phase 03Control redesign and verification

07 / Current status

Additional controls implemented

All findings were tracked through the described remediation phase. Status reflects the case-study review lifecycle.

08 / Case-study summary

The assessment resulted in additional approval boundaries and automated withdrawal controls.

Technical case study — not an audit certificate