The threshold
Private key material is generated and held under multi-party computation with a 2-of-3 threshold. No party ever holds a complete private key. A valid signature requires the threshold. The full key is never reconstructed in one place.
Why one shard is operational
A shard retained under platform operational design is not a custody claim on user assets. It is what lets the system apply post-quantum seals, short-cycle rotation, and policy co-sign without unilateral spend.
Wallet
This is the model behind getjil.com. No seed phrase to lose. Recovery follows a structured ceremony. Hardware wallets still protect keys at rest; JIL protects assets in motion.
In practice
- User retains a shard
- Compromise of one shard is insufficient to move assets
- Target 72-hour operational rotation in production configurations
- Works alongside hardware wallets, does not replace them
Questions people actually ask
Is this self-custody?
The user holds a shard and authorizes signs. Absolute self-custody claims should be read against the published wallet model.
What if one shard is lost?
Recovery is a ceremony using the remaining threshold, not a 12-word backup string.
Keep reading
The white paper and a briefing are the next step if you are evaluating a cell.