Home · Learn · Custody

Threshold storage today, not threshold signing

Most systems secure the door. JIL secures the assets inside the vault.

The threshold

Private key material is generated under a 2-of-3 threshold. On the default service key, shares are created server-side and signing reconstructs the secret in memory. You authorize every sign. This is not 'only you hold keys'.

Why one shard is operational

A shard retained under platform operational design is not a custody claim on user assets. It is what lets the system apply post-quantum seals, short-cycle rotation, and policy co-sign without unilateral spend.

Wallet

This is the model behind getjil.com. No seed phrase to lose. Recovery follows a structured ceremony. Hardware wallets still protect keys at rest; JIL protects assets in motion.

In practice

  • You authorize every sign; the default key is not a user-held shard
  • Compromise of one shard is insufficient to move assets
  • Target 72-hour operational rotation in production configurations
  • Works alongside hardware wallets, does not replace them

Questions people actually ask

Is this self-custody?

You authorize every sign. The default key is generated and stored server-side. This is not self-custody in the 'you hold the only key' sense.

What if one shard is lost?

Recovery is a ceremony using the remaining threshold, not a 12-word backup string.

Keep reading

The white paper and a briefing are the next step if you are evaluating a cell.