Eight layers standing between an attacker and your deposit.
TrustWalletLedger Treasury Vault treats security as a stack, not a slogan. Each of the controls below is documented, independently audited where applicable, and disclosed to institutional clients on request.
Certified for Global Security Excellence
TrustWalletLedger is officially certified for both ISO/IEC 27001 (Information Security Management) and ISO/IEC 27701 (Privacy Information Management). These globally recognized standards are a testament to our unwavering commitment to protecting your data and assets with the highest level of security and privacy controls.
These certifications were awarded following a rigorous independent assessment by A-LIGN, a leading security and compliance auditing firm.
To ensure we continually meet these world-class standards, TrustWalletLedger undergoes regular, ongoing surveillance audits. This means our security and privacy systems are constantly monitored and improved to stay ahead of evolving threats.
The eight protocols in detail
Click any protocol to expand its detail. Diligence packs for institutional clients include full evidence for each.
Deposited assets settle into segregated cold vaults at licensed sub-custodians. Movement out of cold storage always requires a 3-of-5 multi-signature quorum with hardware-backed signers held in three separate jurisdictions.
- Assets held with qualified, regulated digital-asset sub-custodians (disclosed under NDA during institutional diligence).
- ≤ 5% of any asset is held in insured hot-wallet transit for redemptions.
- Hardware signers rotated on a 90-day schedule; ceremony recorded and independently attested.
- No single officer — including the CEO — can move client assets unilaterally.
See the biometric step-up in action
A live illustration of how the step-up policy behaves. Enter an amount and try the prompt.
Emergency recovery, without exposing your seed
A four-step process guarded by identity, cool-down, and a human attestation.
Request from your account email
Sign in on any device using your account email. Choose Emergency recovery from the security menu. No seed phrase, ever.
Shared responsibility
Security is a partnership. Here is who owns what.
| Control | TrustWalletLedger | Account owner |
|---|---|---|
| Cold-storage custody of deposited assets | — | |
| Multi-sig ceremony and hardware signer rotation | — | |
| Smart contract audits and bug bounty | — | |
| Insurance tower and claims administration | — | |
| Sanctions and behavioural transaction monitoring | — | |
| Data encryption at rest and in transit | — | |
| Enabling MFA and biometric step-up on your device | — | |
| Keeping your account email secure and up to date | — | |
| Managing the wallet addresses you whitelist | — | |
| Reviewing your audit trail and reporting anomalies |
Institutional clients can request the full evidence bundle: audit reports, SOC 2 Type II letter, insurance schedule, penetration test summary, and monthly proof-of-reserves attestations.
Request diligence packSecurity researchers can submit findings through our coordinated disclosure program. Critical findings are eligible for bounties commensurate with severity.