OUR SPECIALTY · VAULT-GRADE CUSTODY
Multi-Vendor Bitcoin Multisig Vaults for Families
A vault for your family's Bitcoin where no single device, no single company, and no single lost key can cost you the position.
A multi-vendor multisig vault is the most robust way a family can hold Bitcoin: several keys, on hardware from independent manufacturers, kept in separate locations, with a written protocol for how they are used and inherited. It is what we build in our Legacy engagement, and it is the part of this work we have chosen to specialise in. This page explains what it is, why the multi-vendor detail matters more than most people realise, and why the setup is worth doing properly or not at all.
What is a multisig vault?
Several keys, one quorum, no single point of failure.
A standard Bitcoin wallet is controlled by one key. Whoever holds that key holds the Bitcoin — and whoever loses it, loses the Bitcoin. Every classic self-custody disaster, from the house fire to the forgotten seed phrase to the coerced transfer, traces back to that single point of failure.
A multisig vault replaces the single key with a quorum. In a 2-of-3 vault, three keys exist and any two must sign together before Bitcoin can move. In a 3-of-5, five exist and three must agree. The consequences are profound: a thief who finds one key gets nothing. A fire that destroys one key costs nothing. A single compromised computer can no longer authorise anything on its own. The vault tolerates failure — which is exactly what long-term family capital requires, because over decades, something always fails.
Why does multi-vendor matter?
Companies fail more often than mathematics does.
Here is the detail most multisig setups get wrong: if all of your keys live on devices from the same manufacturer, you have not eliminated your single point of failure — you have moved it. You are now trusting one company's firmware, one company's supply chain, one company's update process, and one company's continued existence, with every key at once. A critical firmware bug, a malicious update, a compromised batch of devices, or a manufacturer simply going out of business now touches your entire quorum simultaneously.
These are not theoretical concerns. Hardware wallet vendors have shipped critical vulnerabilities, suffered data breaches, and made design decisions that alarmed their own users. No manufacturer — however reputable — deserves to be a single point of failure for a family's patrimony.
A multi-vendor vault applies the logic of multisig to the companies themselves. Each key lives on a signing device from a different, independent manufacturer, running independent firmware. For any vendor-level failure to threaten your Bitcoin, two or more unrelated companies would have to fail in compatible ways at the same time. That is the standard serious holders are converging on, and it is the standard we build to.
"No manufacturer — however reputable — deserves to be a single point of failure for a family's patrimony."
What does "no single point of failure" really mean?
The list of events your vault simply survives.
Designed and executed properly, a multi-vendor multisig vault survives, without loss and without drama: a house fire or flood at any one location. The theft or loss of any one device or backup. A critical firmware flaw or supply-chain compromise at any one manufacturer. Malware on the family computer. The death or incapacity of the principal holder. And — because your family holds every key — it survives anything that happens to Schelling Point. We design the system so that it does not need us.
The corollary is a discipline: keys in separate physical locations, backups that are tamper-evident and geographically distributed, and a written record of what exists and where. Redundancy that exists only in someone's head is not redundancy.
Why shouldn't families do this alone?
Done wrong, multisig is less safe than a single key done well.
Multisig is unforgiving of casual execution, and the failure modes are quiet ones — invisible on the day of setup, catastrophic years later. The well-documented pitfalls: cosigner keys that were never verified on the devices themselves, leaving room for a compromised computer to substitute an attacker's key during setup. Receiving addresses trusted from a screen that malware can repaint. And the one that catches nearly everyone — families who carefully back up every seed phrase but not the wallet configuration itself, not realising that in multisig, the seeds alone may not be enough to recover the funds.
A vault with any of these flaws feels secure and isn't. The honest summary of the security literature is that a poorly executed multisig is worse than a well-executed single key. This is precisely why we treat the setup as a formal, verified ceremony rather than an afternoon of plugging in devices — and why every vault we build ends with a rehearsed recovery, not a hopeful assumption.
How we build your vault
A formal process, from threat model to rehearsed recovery.
Design around your family, not a template
We begin with your actual situation: the size of the position, who is in the family, where everyone lives, what must survive what. From that threat model we design the quorum — how many keys, held by whom, in which locations and jurisdictions — and select signing devices from independent manufacturers to fit it.
A guided key ceremony — your hands, not ours
Every key is generated and verified by you, on your devices, with us guiding each step and independently verifying the result. We never see, touch, or hold a key at any point. Cosigner keys are cross-checked on the devices themselves, and the first receiving addresses are verified the same way — closing the exact gaps that quiet DIY failures slip through.
Backups and documentation built for decades
Each key is backed up on durable media, sealed tamper-evident, and placed in separate locations. The wallet configuration — the piece almost everyone forgets — is documented and stored redundantly, alongside plain-language recovery instructions written for the people who will actually need them, not for engineers.
Heirs trained, recovery rehearsed
Your spouse or heirs learn the system with their own hands: signing, verifying, recovering. Then we rehearse the scenario that matters — recovering access without you in the room. A recovery that has never been rehearsed is a hope, not a plan. From there, the annual review under Premium Continuity keeps the vault current as devices, family, and circumstances change.
Who is this for?
The Vault layer of a serious position.
In our framework, Bitcoin is structured into Spending, Savings, and Vault. The multi-vendor multisig vault is how the Vault layer — the long-term patrimony, the portion measured in generations — should be held once a family's position is meaningful enough that its loss would be unrecoverable. It is the centrepiece of our Legacy engagement , and it is maintained through an annual in-person review and recovery rehearsal.
If your position is earlier in its journey, the Foundation and Family engagements build the same discipline at the right scale — and the free assessment will tell you honestly which is appropriate.
Frequently asked questions
Do you hold any of our keys?
No. We never take custody of client funds or keys. We design the vault, guide the setup, and train your family — every key stays in your hands at every stage.
What does "multi-vendor" mean in a multisig vault?
Each key in the quorum lives on a hardware signing device from a different, independent manufacturer. A firmware bug, a bad update, or a supply-chain compromise at any one company can then never affect enough keys to put your Bitcoin at risk.
What happens if one device fails or a manufacturer disappears?
Nothing happens to your Bitcoin. The quorum is designed to survive the loss of any single key. We then guide a calm, planned replacement of the affected key — a routine that is documented and rehearsed in advance.
Can non-technical family members manage this?
Yes. The vault comes with written, plain-language protocols, hands-on training for your spouse or heirs, and a rehearsed recovery drill — so the people who matter can operate the system without us and without technical background.
What if something happens to Schelling Point?
Your vault keeps working. We build exclusively on open Bitcoin standards, and your family holds every key and every recovery document. Nothing about your setup depends on our existence.
Is a multisig vault overkill for our holdings?
Sometimes, yes — and we'll tell you. Multisig is for the Vault layer of a serious position. For smaller amounts, a well-executed single-signature setup with proper backups is often the right answer, and it costs less.
Start with a private conversation
No cost, no obligation. We'll listen to your situation and tell you honestly whether a multisig vault is the right step for your family — or whether it isn't yet.