Oryx
Custody with a quorum and no heroes

Client identities and brand marks are anonymised. Names, logos and interfaces shown are not real companies or real projects.
- Sector
- Digital asset custody
- Location
- Dubai, UAE
- Year
- 2025
- Kickoff to production
- 22 weeks
Institutional custody where every withdrawal needs a quorum, a whitelist and a time lock, and no single person can move anything.
The desk held client assets in a wallet controlled by two people and a shared password manager. Approvals happened on a phone call, transaction policy existed as a document, and an auditor had no way to test either.
Policy in hardware, not in a memo
Limits, whitelists and time locks are enforced by the signing devices themselves, so a policy cannot be talked around at eleven at night.
A quorum by role
Approvals are bound to roles (operations, treasury, risk, compliance) with separation of duties enforced technically rather than by trust.
Recovery rehearsed, not assumed
The key ceremony, backups and recovery path were documented and rehearsed with the client twice before a single asset moved.
The desk passed its licensing review using control evidence the system produces itself, and now onboards institutions that had previously refused it on custody grounds.
What changed
- Signing quorum
- 4-of-6
- Withdrawals
- Whitelist + timelock
- Control evidence
- Licensing-ready
- Rust
- Postgres
- Next.js
- Kubernetes
- HSM
Tell us what's slowing you down.
Fifteen questions, one screen at a time, and a verdict at the end. No call needed to get it.