Secured by Trust Wallet
Security protocols

Eight layers standing between an attacker and your deposit.

TrustWalletLedger Treasury Vault treats security as a stack, not a slogan. Each of the controls below is documented, independently audited where applicable, and disclosed to institutional clients on request.

3-of-5
Multi-sig quorum
95%
Assets in cold storage
$550M
Insurance tower
$5M
Per-account cap
24/7
Monitoring & desk
Independently certified

Certified for Global Security Excellence

ISO/IEC
27001
Certified
Information Security Management
A-LIGN audited
ISO/IEC
27701
Certified
Privacy Information Management
A-LIGN audited

TrustWalletLedger is officially certified for both ISO/IEC 27001 (Information Security Management) and ISO/IEC 27701 (Privacy Information Management). These globally recognized standards are a testament to our unwavering commitment to protecting your data and assets with the highest level of security and privacy controls.

These certifications were awarded following a rigorous independent assessment by A-LIGN, a leading security and compliance auditing firm.

To ensure we continually meet these world-class standards, TrustWalletLedger undergoes regular, ongoing surveillance audits. This means our security and privacy systems are constantly monitored and improved to stay ahead of evolving threats.

View Certification Details
Certificates and audit letters available upon request.

The eight protocols in detail

Click any protocol to expand its detail. Diligence packs for institutional clients include full evidence for each.

Deposited assets settle into segregated cold vaults at licensed sub-custodians. Movement out of cold storage always requires a 3-of-5 multi-signature quorum with hardware-backed signers held in three separate jurisdictions.

  • Assets held with qualified, regulated digital-asset sub-custodians (disclosed under NDA during institutional diligence).
  • ≤ 5% of any asset is held in insured hot-wallet transit for redemptions.
  • Hardware signers rotated on a 90-day schedule; ceremony recorded and independently attested.
  • No single officer — including the CEO — can move client assets unilaterally.

See the biometric step-up in action

A live illustration of how the step-up policy behaves. Enter an amount and try the prompt.

Standard TOTP code required
Biometric step-up required (≥ $25,000)
Second device approval required (≥ $250,000)
Prompt will appear here.

Emergency recovery, without exposing your seed

A four-step process guarded by identity, cool-down, and a human attestation.

Step 1 of 4
Detail

Request from your account email

Sign in on any device using your account email. Choose Emergency recovery from the security menu. No seed phrase, ever.

Shared responsibility

Security is a partnership. Here is who owns what.

ControlTrustWalletLedgerAccount owner
Cold-storage custody of deposited assets
Multi-sig ceremony and hardware signer rotation
Smart contract audits and bug bounty
Insurance tower and claims administration
Sanctions and behavioural transaction monitoring
Data encryption at rest and in transit
Enabling MFA and biometric step-up on your device
Keeping your account email secure and up to date
Managing the wallet addresses you whitelist
Reviewing your audit trail and reporting anomalies
Diligence pack

Institutional clients can request the full evidence bundle: audit reports, SOC 2 Type II letter, insurance schedule, penetration test summary, and monthly proof-of-reserves attestations.

Request diligence pack
Report a vulnerability

Security researchers can submit findings through our coordinated disclosure program. Critical findings are eligible for bounties commensurate with severity.

support@trustwalletledgers.com
PGP fingerprint published in the diligence pack