Security & Governance
Control stays where it belongs
The safest asset is one that a platform can’t move. Trnzit is built on that idea: we coordinate instructions and approvals, and your own providers hold and move your assets.
Why Trnzit exists
Centralised control shouldn’t mean centralised custody
Organisations now hold digital assets across exchanges, custodians and wallets. Managing it usually means either juggling a dozen logins or handing assets to a single intermediary.
Trnzit takes a third route.
It brings every account into one governed view and one point of contact, while private keys and assets stay exactly where you put them.
Your providers keep doing what they do well;
Trnzit makes them work as one system, under your rules.
Principles
Six principles we design to
These describe how Trnzit is designed. They aren’t certifications or audit opinions, and we don’t present them as such.
Non-custodial by design
Trnzit and the Trnznd Group never hold private keys, seed phrases or client assets. Custody stays with you and your chosen providers.
No unilateral control
For organisations, approval policies can require more than one person for any material action, so no single member can act alone. Individual account holders keep sole control of their own accounts.
Least privilege
Trnzit stores the API details you provide to connect each account, with the narrowest access each provider allows.
Separation of duties
The person who requests an action can’t be the person who approves it. Changes to policies follow the same rule.
A complete record
Every request, approval, rejection and policy change is recorded with who did it and when, ready for your own audit and records.
Revocable by you
You can disconnect any provider from Trnzit, or withdraw access at the provider directly, at any time.
Our commitments
What Trnzit will never do
- Hold your private keys or seed phrases
- Take custody of, pool or hold client assets
- Transmit funds, or route them through a Trnzit account
- Execute a transaction that your policies haven’t approved
- Give investment advice or manage assets on your behalf
Not by email, phone, chat or in the app. Anyone who asks for them is not Trnzit. Report it to [security contact email].
Governance controls
Your governance, enforced in software
Trnzit turns the rules your board, finance committee or family office already follows into policies that are applied to every request.
- Authority levels for viewers, initiators, approvers and administrators
- M-of-N approvals by amount, connection, asset or action type
- Address whitelisting, with whitelist changes subject to approval
- Policy change control, so rules can’t be edited by one person
- Outside-activity alerts: a transaction on any connection that wasn’t made through Trnzit triggers an email and an in-platform notification to the people you choose, sent as soon as it’s identified. Monitoring covers Ethereum, Solana and Tron only
Security practices
How we protect what we store
Trnzit stores the API details that connect your accounts. It never stores private keys, signing keys or seed phrases.
Draft · typical practice · to be confirmed by Trnzit’s technical team before launch
Stored API details
API details are encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Encryption keys are managed in a dedicated key management service, kept separate from application data, and API details are only decrypted when an approved instruction is sent.
Least-privilege access
We ask each provider for the narrowest permissions a feature needs, and we recommend restricting API details to known IP addresses where the provider supports it.
Member sign-in
Multi-factor authentication is required for every member: a magic link sent to their email, plus a code from an authenticator app. It protects your sensitive information and access to your connected providers. Sessions time out after a period of inactivity.
Our own access
Access to production systems is limited to named staff, protected by multi-factor authentication and logged. No staff member can view stored API details in plain text.
Testing & monitoring
Systems are monitored continuously and tested by independent penetration testers. Results will be summarised here once a test has been completed.
Incidents
If an incident affects your data, we’ll notify you without undue delay and tell you what happened, what it means for you and what we’re doing about it.
Still to add, once confirmed: hosting region and data residency, any completed audits or certifications, and regulatory status by jurisdiction.
Found a vulnerability?
Please tell us privately so we can fix it. Email [security contact email]. [Confirm disclosure policy and response times]
Start in minutes
One login. Every account. Your controls.
Connect the accounts you already have, set the rules your organisation already follows, and see everything in one place. Custody never moves.