Most companies don't lose their crypto in a hack.They lose it on a Tuesday.
The founder is in surgery for a week. The CFO resigns over a weekend. The treasurer's laptop disappears at a conference. None of these are exotic. All of them are fatal if one person held the only key.
Above: two of three signers approve before anything moves. No single laptop, no single human, no single Tuesday can empty the treasury.
Trusted contacts can extend. Nobody can lock.
Guardians are the answer to "what if I'm hospitalised, what if I'm sailing, what if my phone is at the bottom of a river?". Each can extend your deadline. None can withdraw. The cap is on-chain.
- Session budget · 90 days
Any single block of extensions from this guardian, capped at 90 days. Resets when the owner checks in.
- Lifetime budget · 180 days
Across the vault's whole life, this guardian can never push the deadline more than 180 days. Hard cap, never resets.
- Cooldown · 24 hours
A guardian who extends today must wait a day before extending again. A single-guardian sympathy event cannot lock the funds out indefinitely.
Self-custody is right. Solo-custody isn't.
Self-custody is the right idea for a company holding crypto. One person holding the only seed phrase is the wrong execution of it. And it's still surprisingly common. We see it constantly: a two-person founding team with a single signer wallet, or a CFO who also happens to be the only one who knows how MetaMask works.
The QuadrigaCX story ($3.7B locked when its founder died, 115,000 customers, no recovery) is the headline version. The version we hear more often is quieter and never written up: a CFO leaves on bad terms and the founders don't sleep for three weeks. A founder is hospitalised and payroll slips two cycles. A laptop is stolen at ETHDenver and the multisig now has fewer signers than its threshold.
What a company actually needs
Not as many features as treasury vendors think. Four things, really.
One. No single person can move large sums alone. That's just multisig. Most companies get this part. They open a Safe (or whatever), put two or three signers on it, and call it done.
Two. If a signer disappears for any reason (resigns, dies, loses the laptop, gets phished, falls out with the team), the others can still operate. Plain multisig doesn't give you this. If you set a 2-of-3 and one signer goes dark, you can still transact, sure. But if two go dark, or if the team agrees to remove one and there's a dispute, you're stuck. Most companies don't think about this until it happens.
Three. The same vault should be able to run the scheduled stuff a finance team does anyway: founder vesting, advisor payments, employee token grants, contributor pay, a monthly transfer to a co-founder's wallet under a buyback agreement. Not because it's a flashy feature, but because handling those transfers manually is exactly when humans miss wires.
Four. Every dollar in and out of the treasury should be readable by your accountants the same week, without anyone having to remember to log it. On-chain transactions are already the cleanest audit trail in finance. We just don't usually present them that way.
How HeirVault solves it
Our model is the same one we use for families, applied to a company: a quorum of named signers, a periodic heartbeat from whoever owns ops, a recovery path if the entire group is unreachable, and a standing-orders engine for everything that should be on a schedule.
A real configuration looks like this. The board agrees on a 2-of-4 quorum for any outflow above $50k: two cofounders, the CFO, and one outside director. Below the threshold, ops can transact with a single signature for daily stuff. The CFO checks in every 30 days(literally a one-click confirmation: "I'm here, the team's here, nothing's wrong"). If the check-in is skipped for 60 days, the rest of the quorum can recover the seat over a 7-day window. They can also cancel that recovery from any device, at any point, if it turns out the CFO was just on holiday.
Founder vesting runs in parallel: $25k per quarter to a former cofounder under a buyback, set once, the contract handles the rest. The recipient claims when they want. The schedule cannot be accelerated. It can be paused by the company any time, and cancelled outright if needed.
When the auditors arrive, every transaction is on-chain, signed by named entities, with timestamps that aren't negotiable. The CSV export takes a minute.
"We rebuilt the treasury the week our last CFO left. It took an afternoon. The board signs together for anything above $50k. When our ops lead got COVID for two months, nobody panicked. That alone has paid for the subscription a hundred times over."
Treasurer, Series B fintech
What's actually hard about setting this up
Not the tech. The tech part is a couple of hours from a wallet. The hard parts are the decisions, and we'll be honest about them.
Who's on the quorum, and what's the threshold?Most teams pick 2-of-3 or 3-of-5. Smaller is faster to operate and more fragile. Larger is more robust and harder to coordinate. A board director or trusted outside lawyer in the mix tends to be the right call, because it forces a conversation before money moves.
Where does recovery go? This is the part most companies skip. If your entire quorum is unreachable (a single accident, a falling-out, a coordinated phishing attack), where does control land? Usually a backup wallet held by legal counsel or the audit committee. It feels like overkill until you need it.
How often is the heartbeat? Active operating treasuries: 30 days. Cold reserves: 90, sometimes 180. We've seen one company set 24 hours for their hot wallet, which is aggressive but defensible if your ops team is genuinely full-time.
What's the threshold for "large"? Below the quorum threshold, ops can transact single-sig. Above it, the board has to sign. Most teams land between $25k and $100k. Set it too low and ops drowns in approvals. Set it too high and the whole point is gone.
What this won't do for you
We're not a bank, an accounting system, or a corporate lawyer. We don't handle fiat rails, file your taxes, draft your operating agreement, or tell you what your local regulator thinks about a token grant. Tax software, your accountant, and your jurisdiction's actual lawyers handle that. We just make sure every on-chain action is exportable in a format they can actually use.
We're also not a hedge against bad governance. If your team can't agree on a 2-of-3 threshold, multisig isn't your problem. If your founders won't talk to each other, no smart contract fixes that.
What to do next
If you're configuring this for a team with multiple stakeholders, book a concierge call. We've helped DAOs, family offices, and operating businesses set quorum and recovery cleanly. Founders take the call. The whole thing takes 30 minutes, sometimes 45 if there's a tricky governance situation to talk through. We never see your keys.
Ready to set this up?
Or book a concierge call to talk through quorum and recovery before you set anything up. Founders take the call. We never see your keys.