Alph AI Security Vault

Bank-Grade Security Vault

There is no private key. Ever.

Alph AI · MPC Keyless Security System

If it breaks, we pay.

Alph AI elevates wallet security to a system-grade capability: MPC keyless, zero-attack-surface isolation, AWS Nitro Enclaves, and full-path risk control—bank-grade, verifiable, auditable, reusable.

Hackers can’t steal what never exists.

Zero-Trust SecurityMPC / TSSTEE EnclaveRisk Shield
7-layer defense architecture

Security Summary

“There is no private key. Ever.”

Private keys never fully exist; the attack surface disappears at the root. Asset security relies on verifiable cryptography and physical isolation, not single-point trust.

SOC2 / ISO 27001 Aligned
Tiered Permissions + Audit Trails
Cross-Domain Isolation + Zero Surface
End-to-End Risk Control

7-Layer Defense

Alph.ai 7-Layer Defense

01

MPC 3-of-3 / 2-of-3

“Keyless” design: the key is split into 3 shards, signing needs only 2; the full key never exists.

“Hackers can’t steal what never exists.”

02

Isolated Signing Service

“Zero Attack Surface”: signing runs in fully isolated networks with no external entry points.

“Not just defense—there is no path in.”

03

Physical / Network Isolation

Independent security domains with physical isolation. Compromise in one node can’t spread.

“Mutual distrust is the strongest trust.”

04

TEE(AWS)

“Bank-grade isolated vaults”: sensitive computation happens only inside AWS Nitro Enclaves.

“Verifiable execution in isolated enclaves.”

05

Multi-Factor Key Control

No single key can unlock. Attackers must compromise multiple teams, systems, and layers.

“Attack difficulty grows exponentially.”

06

Signature Path Verification

End-to-end auth for every signing request with anti-forgery and anti-replay checks.

“Every transaction has an ID.”

07

Zero-Trust Ops

MPC for ops: no single insider can access critical steps. Everything is audited.

“Eliminate insider abuse.”

Core idea: turn attack cost from addition to multiplication. No single layer compromise reaches assets.

Keyless Vault

MPC / TSS Wallet System

Distributed key generation and threshold signing turn attack cost from addition to multiplication. The full private key never exists; single-point leaks are ineffective.

Key Sharding

Key shards only; the full key never exists.

Threshold Signature

2-of-3 / 3-of-3 threshold co-signing.

Security Domains

Multi-domain isolation + no public signing nodes.

Sig = f(share1, share2, ..., sharek), k ≥ t

Distributed Key Generation (Illustration)

Traditional: generate full private key →private_key = generate_private_key()

MPC: distributed shard generation →shard_1, shard_2, shard_3 = generate_shards_in_distributed_manner()

Key point: no device/person ever sees the full private key.

MPC wallet system
Threshold2-of-3 / 3-of-3
Key MaterialNever Exists
Attack SurfaceZero Surface
Trusted execution environment (TEE)

TEE Enclave

Trusted Execution Environment (TEE)

Shard decryption and signing occur only inside the enclave. Remote attestation verifies integrity and mitigates memory extraction and supply-chain risks.

  • AWS Nitro Enclaves
  • Memory encryption + sealed storage + remote attestation
  • Cross-platform secure base to reduce single-vendor dependency

Zero-Trust Infrastructure

Zero-Trust Infrastructure

Zero-Trust Ops Principles

  • Four-eyes rule: critical actions require two independent approvals.
  • Time-bound access: temporary privileges auto-expire.
  • Behavioral baselines: anomalies alert in real time.
Zero-trust infrastructure

Network Topology

Network Topology: Zero Attack Surface

Internet (Public)
Outbound Only
Reverse Proxy / API Gateway
App Layer (No Signing)
Isolated Signing (No Public IP)
Tokyo DC
TEE Cluster · Shard B1
Private Link
Frankfurt DC
TEE Cluster · Shard B2
Private Link
Virginia DC
TEE Cluster · Shard B3

Pre-Trade Risk Scan

Contract Risk Pre-Check Pipeline

Within milliseconds after you input a contract address, the system runs rules, symbolic execution, and AI semantic analysis in parallel to produce a structured risk report and recommendation.

  • Address input → fetch bytecode
  • Parallel analysis (< 3s)
    • Rules engine: match 300+ risk patterns
    • Symbolic execution: detect hidden logic paths
    • AI semantics: infer real contract intent
  • Structured report
    • Risk score (0–100)
    • Key risks (taxes, blacklist, etc.)
    • Recommendation (block / warn / allow)
Buy/Sell Tax TrapDynamic BlacklistNo LP LockOver-Centralized ControlToken FreezingFake Liquidity

Execution Simulation

In-Trade Execution Simulation

Simulate critical scenarios in parallel to assess slippage tolerance and sandwich risk to avoid failed executions.

  • Slippage shock: price impact tolerance
  • Gas volatility: cost control check
  • MEV sandwich: anti-front-running simulation
  • Callback: re-entrancy defense
  • Extreme moves: cliff-drop risk

Post-Trade Monitoring

Post-Trade Holdings & Liquidity Monitoring

Execution is the start of risk. We continuously monitor holdings, LP changes, and permission changes, triggering alerts and providing stop-loss and replay tools.

  • LP volatility & withdrawal alerts
  • Top holder movement detection
  • Permission changes & upgrades
  • One-click stop loss + risk replay

MPC × Risk Engine

MPC Signing Interlock

Risk controls are tightly coupled with MPC signing to form a detect–block–audit loop. High-risk transactions can be denied before signing.

  • Risk score < 30: deny signing
  • Rug confirmed: trigger temporary freeze
  • Blocks logged into zero-trust audit

Audit & Transparency

Audit & Transparency

All signing requests, TEE attestations, and network metadata are auditable. Quarterly penetration testing and protocol verification sustain transparency over time.

  • Real-time audit: signing logs + attestations
  • Quarterly third-party tests & formal verification
  • Public transparency reports & bug bounty updates

Security Team

Bank-Grade Security Team

The security vault is designed and maintained by a team spanning TradFi and Web3 security expertise.

Core Lead

Led by CTO Evan, the team has led key audits, fixed critical vulnerabilities, and presented on on-chain signing.

  • Led major CertiK audits
  • Fixed multiple critical issues
  • Shared on-chain signing practices

Cross-Disciplinary

Core members span TradFi and Web3 security firms with 150+ DeFi, Layer1, and bridge audits.

  • From top banks / payments risk teams
  • SOC2 / ISO 27001 expertise
  • From CertiK, Quantstamp, PeckShield

Strategic Partner

Partnered with Bitrue’s 8-year security team to strengthen on-chain asset protection.

We’re building a bank-grade security vault, not just a trading platform.

Alph Video

Private keys should never exist.

How MPC makes hacks impossible

Experience a bank-grade secure trading bot for faster, safer, more reliable on-chain execution.

Get Started