Custody, controls and evidence
Stablerail is self-custodial software. Keys stay with the customer under MPC, every outgoing payment passes policy and screening, and every action leaves an audit record a finance team can hand to an auditor.
Custody model
Stablerail runs on Privy MPC infrastructure (owned by Stripe). Private keys are split into shares that are never combined: the whole key does not exist at any point in its lifecycle, and signing takes place inside hardware-isolated environments. Stablerail holds no share that lets it sign alone, so it cannot unilaterally move customer funds.
- No whole private key ever exists — MPC threshold signing only.
- Signing executes in hardware-isolated enclaves, not in application code.
- Quorum-protected key export means customers can leave with their keys.
- Stablerail is not a custodian and cannot initiate transfers on a customer's behalf.
Payment controls
- Policy engine: per-counterparty, per-amount and per-asset rules applied before a payment can be proposed.
- Approvals: multi-approver workflows with named requesters and approvers on every payment.
- Screening: sanctions and wallet-risk checks against counterparties before funds move.
- Anomaly detection: AI flags outliers — first-time counterparties, unusual amounts, off-hours activity — and explains why.
Audit evidence
Each transaction stores the full operating record: who requested it, who approved it, which policy applied, what screening returned, which counterparty was involved, and the on-chain result. That record is exportable, so month-end close and audit requests do not depend on chat history or screenshots.
Platform and data security
- Data encrypted in transit (TLS) and at rest.
- Role-based access control for team members, with least-privilege defaults.
- Row-level authorisation on all customer data; internal tooling is separated from customer-facing systems.
- Fiat rails and card issuing run through regulated partners with their own supervisory regimes.
Report a suspected vulnerability to security@stablerail.com. We acknowledge reports and respond with a remediation plan.
Frequently asked
No. Stablerail is self-custodial. Keys are generated and used under MPC, so the full private key never exists in one place, and Stablerail cannot sign or move funds on its own.
Stablerail is built on Privy MPC infrastructure (owned by Stripe). Key shares are held separately and signing happens inside hardware-isolated environments.
Yes. Customers can export their keys at any time through a quorum-protected flow, so there is no lock-in to Stablerail as a platform.
No. The AI screens counterparties, flags anomalies and explains risk. It never signs transactions and never bypasses policy. Humans approve and sign.
Neither. Stablerail is a non-custodial software platform. Fiat rails and card programmes are provided by regulated third-party partners after KYB.
One account for stablecoin treasury, cards and payouts.
Receive, approve, screen, pay, card-spend and off-ramp — with audit evidence on every transaction.
