tranquillo.io custody
A self-hosted cryptographic signing and key management server — built for production environments, split-seed HD key derivation, and native PKCS#11 hardware security module integration.
- Client registry with per-tenant HSM tokens, auto-provisioned PKCS#11 slots, and encrypted credential storage
- BIP-32 HD key derivation across 15+ assets — seeds are never stored, reconstructed on demand via HMAC-SHA512 split-seed architecture
- Challenge-response approval workflows — admins create derivation or recovery requests, mobile device holders approve with client entropy
- HSM slot management with token initialization, PIN rotation, mechanism inspection, and key lifecycle operations
- Append-only audit logging for all mutating operations with server-side filtering, pagination, and free-text search
- Multi-user JWT auth with Argon2-based password hashing and role-based access control