Assessment archive
Institutional Asset Custody / Assessment case
Obsidian Custody
Additional controls implemented
01 / System overview
A policy-governed custody environment separating transaction intent, approval and cryptographic execution.
The assessment resulted in additional approval boundaries and automated withdrawal controls.
02 / Architecture diagram
N1Request Portal
N2Policy Engine
N3Approval Quorum
N4Signing Enclave
N5Settlement Vault
03 / Assessment scope
Multisignature policies
Approval workflows
Key generation
Transaction limits
Disaster recovery
04 / Threat model
T-01
Approval collusion
T-02
Policy bypass
T-03
Key ceremony failure
T-04
Unbounded transaction
05 / Findings by severity
High0
No critical asset-loss path was reproduced.
Medium4
Approval separation and transaction-limit enforcement.
Low3
Recovery evidence and policy observability.
06 / Remediation timeline
Phase 01Authority and policy mapping
Phase 02Workflow abuse and recovery simulation
Phase 03Control redesign and verification
07 / Current status
Additional controls implemented
All findings were tracked through the described remediation phase. Status reflects the case-study review lifecycle.
08 / Case-study summary
“The assessment resulted in additional approval boundaries and automated withdrawal controls.”
Technical case study — not an audit certificate