AERKey. The wallet. The policy engine. The Agent Control Center. Four pillars of one platform, built on a single idea: nothing signs unchecked, and everything is on the record.
Every custody disaster you have read about — the exchange that lost a billion dollars, the founder who walked away with the keys — comes down to the same flaw: somewhere, a complete private key existed, and someone got to it.
AERKey removes that flaw at the root. With AERKey, your signing key never exists. Not in a vault, not in a hardware module, not for a millisecond in memory. Three independent machines each hold a fragment that is useless on its own, and each fragment lives inside a sealed hardware enclave that even AEREDIUM's own engineers cannot open. When a transaction is approved, the three enclaves run a cryptographic protocol together and a valid signature emerges — yet at no point, anywhere, is the key ever assembled. There is nothing to steal, nothing to leak, and no insider who can walk out the door with your funds.
The mathematics behind this is threshold cryptography. AERKey runs CGGMP24, the most advanced threshold signing protocol published to date — the latest iteration of the protocol family trusted by the largest institutional custodians. It produces ordinary signatures that every blockchain accepts natively, and if any party misbehaves during signing, the protocol identifies the culprit rather than failing silently.
A key that cannot be stolen still needs to be governed, because the signature only says who — policy says whether. Every request passes through the policy engine before any enclave will act: per-transaction limits, approval quorums (if your policy allows one signer up to $5,000, a $6,000 transfer requires a second approval), destination allowlists, verified identity, and a biometric confirmation bound to the exact transaction. The enclaves refuse to sign without cryptographic proof that policy approved this specific transaction — your rules are enforced by the same hardware that signs, not by a web server in front of it.
The AERKey Wallet is that architecture put in your hands. It is a custodial wallet with nothing to custody in the old sense: there is no seed phrase to write down, lose, or have phished, because there is no key to back up. Your accounts live on the threshold cluster itself, and you approve each transaction with your own biometrics, bound to the exact transaction in front of you — not a session, not a login, that transaction.
Every single transaction the wallet sends is tested before it is signed. That test is the job of the policy engine. A policy is simply your treasury rules written in enforceable form: who may move funds, up to what amount, to which destinations, and how many approvals each transfer requires. You write the rules; the system enforces them without exception or override. The policy engine evaluates every transaction against your policy and issues a cryptographically signed verdict, the enclaves refuse to act without verifying that verdict, and the resulting signature is itself verified before anything leaves the system. A stolen phone, a phished password, even a coerced employee cannot move what the policy does not allow. That is what makes the AERKey Wallet a safe custodian wallet: its safety is not a promise from a company holding your key — it is a property of a system in which no one holds it, nothing signs unchecked, and everything is on the record.
The same discipline is how we make AI agents safe to trust with money. An agent is tireless, fast, and utterly literal — which makes it powerful, and makes an ungoverned one dangerous. In the AERKey Wallet, every owner can create child wallets, and each child wallet belongs to exactly one agent: one agent, one wallet, one policy, with no sharing and no ambiguity about who did what. Each agent's wallet is attached to one of our twelve agent policy templates, so an agent operates inside limits you chose before it ever moved a cent — how much, how often, to whom — and the enclaves enforce those limits on the agent exactly as they do on a human. An agent cannot exceed its policy for the same reason an employee cannot: the rules are not suggestions to the software, they are conditions of the signature itself. This is AER360 — AERKey, the wallet, the policy engine, and the Agent Control Center, working as one platform. Watch the video to see it come together.
AERKey, the wallet, the policy engine, and the Agent Control Center — one platform, in motion.
And every event — every request, approval, refusal, and signature — is written to a tamper-evident audit chain, sealed by the threshold cluster itself. The audit is not a log an administrator could quietly edit; it is cryptographic evidence, verifiable years later.
Key, policy, audit — one system. The key that cannot be taken, the policy that decides, and the record that proves it. That is the trust layer.