Enterprise Security

Japan’s only HSM-First custody

Private keys = ownership. Three layers, integrated.

01 Defense in depth

Three layers, one custody core

Hardware keeps the keys, MultiSig spreads the authority, and the policy engine decides what is allowed.

HSMFIPS 140-3 L3
Policy engine MultiSig · M-of-N Keys never leave the hardware
HSM

Hardware Security Module

Keys never leave tamper-resistant hardware. FIPS 140-3 Level 3 certified — with NexBridge custom FM running inside the secure boundary.

  • FIPS 140-3 Level 3 certified hardware
  • Keys never leave tamper-resistant hardware
  • NexBridge custom FM runs inside the secure boundary
Secure boundary NexBridge custom FM
Luna HSM · FIPS 140-3 Level 3
MultiSig

Multi-Signature

No single key can authorize transactions. M-of-N threshold across institutional signers.

  • No single key can authorize a transaction
  • M-of-N threshold across institutional signers
  • For example, 2-of-3 approval required
Signer AApproved
Signer BApproved
Signer CNot needed
2 / 3Threshold met → sign
Illustrative 2-of-3 threshold
Policy Engine

Programmable Approval Workflows

Encode compliance, velocity limits and approval logic at the protocol layer.

  • Compliance rules encoded at the protocol layer
  • Velocity limits on transfers
  • Approval logic enforced by the policy engine
Illustrative policy

02 Architecture

Four layers from request to settlement

API gateway and compliance, key management and signing, air-gapped cold storage, and the blockchain settlement layer.

API gateway + compliance layerL1
Key management & signingL2
HSMHardware keys
MultiSigM-of-N auth
Policy engineGuardrails
Air-gapped cold storageL3
Blockchain settlement layer LiveL4
Request flow · top to bottom

03 Cross-border settlement

Privacy and compliance, built into settlement

Cross-border P2P settlement with ZK privacy and compliance audit.

Sender · Bank ATokyo, JP
ZK privacy poolCompliant + private
Receiver · Bank BSingapore
On-chain settlement · ZK privacy · Compliance audit

Official Technology Partner

Custom FM for Thales Luna HSM

Officially selected into the Thales Accelerate Partner Network. NexBridge engineers custom Functionality Modules (FM) that run inside FIPS 140-3 Level 3 certified Luna HSMs — the hardware core of the NexBridge Wallet.

Read the announcement

For Financial Institutions

Power your stablecoin strategy

Explore how NexBridge can power your stablecoin strategy — from issuance to custody to DeFi connectivity.