We just completed a full security audit with Adevar Labs.
COSIGNER · COMING SOON

Sign from a hardware enclave

Cosigner is an independent signer that Fystack never controls. It holds its own key share, decodes every transaction locally, and shows you exactly what you are about to sign — before a signature exists.

Fystack mobile cosigner decoding a 1,000 USDC transfer on Sepolia Ethereum, with the signing input match verified before hold-to-sign

/WHAT YOU SEE IS WHAT YOU SIGN/

Validate the transaction locally, before it is signed

The cosigner does not trust the request it receives. It decodes the raw payload itself, checks it against your policies, and asks you to confirm the result — so what appears on screen is provably what gets signed.

DECODED ON THE COSIGNERMATCHES RAW PAYLOAD
Chain
Base
Contract
USDC · 0x8335…2913Verified
Method
transfer(address,uint256)
Recipient
0x510e94…e56370Whitelisted
Amount
10.00 USDC ≈ $10.01
Network fee
0.00021 ETH ≈ $0.68
Calldata decoded on-device — not by the server that requested it
Recipient matched against your address book and travel-rule list
Amount, limits, and policy re-evaluated inside the enclave
RejectHold to sign

Blind signing

No opaque hex to approve. The cosigner renders the human-readable intent of the payload, and refuses anything it cannot decode.

Tampered payloads

If a compromised backend or middleware alters the recipient or amount after a request is created, the decoded view no longer matches — and signing stops.

Address poisoning

Look-alike addresses from clipboard swaps or dusting attacks are caught against your address book before the signature is produced.

Malicious approvals

Unlimited token approvals and unexpected contract calls are surfaced explicitly instead of hidden inside calldata.

/HOW IT WORKS/

A key share you hold, in hardware you control

01

Pair with a scoped token

Enroll a device or a server with a one-time pairing token bound to a single workspace. Pairing can be revoked at any time without touching the wallet.

02

Generate a share in the enclave

The key share is created inside Secure Enclave, StrongBox, or a server TEE, and never leaves it. Fystack never sees it and cannot reconstruct it.

03

Decode and verify locally

Every sign request is decoded on the cosigner itself, checked against your policies, and displayed in full before anything is approved.

04

Contribute a partial signature

On confirmation the enclave produces its part of the MPC signature. Without it the threshold is never met and the transaction cannot settle.

/TWO FORM FACTORS/

A phone in your pocket, or a daemon in your infrastructure

Fystack mobile cosigner pending queue with a USDC sign request and an MPC key generation request, each showing 0 of 1 approved

Mobile cosigner

Approve from a device only your team can unlock

Key share stored in Secure Enclave / StrongBox
Hold-to-sign with biometric confirmation
Full transaction decoding on-device
Push notifications for signs and key generation

Server cosigner

A headless signer running in your own infrastructure

One-command install with a scoped pairing token
Policy engine validates and signs programmatically, 24/7
Runs on your VPC — Docker, Kubernetes, or bare metal
Attested TEE execution with full audit logs
ops@treasury — cosigner
$

/INSIDE THE APP/

Every approval, on the record

The mobile cosigner is not just an approve button. It keeps the full context of what was requested, what was signed, and what this device has authorized.

Fystack mobile cosigner approval timeline showing the raw signing input, 0 of 1 approvals, and the request, signing, and completion stages

Approvals and timeline

The raw signing input, who still has to approve, and every stage from request to settlement.

Fystack mobile cosigner transaction history showing a confirming 1,000 USDC transfer on Sepolia Ethereum

Transaction history

Everything you signed, with live confirmation status and the destination address.

Fystack mobile cosigner activity log listing approved wallet setup and transaction signing events with timestamps

Activity log

An audit trail of every wallet setup and signing event this device approved.

/USE CASES/

Where a second signer changes the risk profile

Treasury with human approval

Finance operators hold the mobile cosigner. Large withdrawals cannot leave the treasury until a named person reviews the decoded transaction and signs.

Automated payouts with a guardrail

The server cosigner signs high-volume payouts around the clock, but only when the decoded transaction satisfies your policy — amount, destination, and chain.

Provable separation of duties

Fystack orchestrates, your cosigner authorizes. Neither side can move funds alone, which is exactly what auditors and regulators want to see.

Cosigner is rolling out soon

Tell us how your team approves transactions today and we will bring you into the early access group for both the mobile and server cosigner.

Join the waitlist
Join our community