CipherSign

Safe payouts with
hard limits.

Lock approved payees and a spending cap. The vault refuses overpay and wrong-person payouts before it signs.

How it works

Coston2 live vault · operator TEE required · fees covered

1

Connect

Open your team vault.

2

Lock rules

Approved payees and a spending cap.

3

Approve

Valid payouts pass. The rest stop here.

Questions

Short answers for operators.

Who is this for?

Finance and ops teams that send fees, payroll, or rewards and cannot afford a wrong address or overspend.

What is live today?

A working Coston2 vault: Lock and Approve on-chain, policy checked in the TEE, explorer proof in-app. The operator TEE must be online. This is a live control plane, not a set-and-forget mainnet treasury yet.

What does Get started do?

Connects your CipherSign vault. Lock and Approve still run on-chain. Gas is paid by the operator sponsor so you are not asked for C2FLR.

Do I pay network fees?

No on the product path. Lock and Approve are gas-sponsored. C2FLR from the Flare faucet is only needed if you run operator tooling yourself.

Where do payee addresses come from?

Copy wallet addresses from MetaMask (or any wallet) and paste them under Rules.

What gets blocked?

Amounts over your limit, and payments to anyone not on the approved list.

Is this a trading app?

No. CipherSign is payout control only, not swaps or trading.

What if the vault is offline?

Lock and Approve need the operator TEE online. If Connect fails, the vault is down (tunnel or Docker stopped). The demo video shows the full flow. CipherSign never signs payouts without the live vault.

Is this hardware attestation?

Hackathon builds use Flare's simulated TEE on Coston2. Production would move to Google Confidential Space attestation after launch.

How do I know an approval is real?

Every approval includes a Coston2 explorer transaction plus a vault signature the app recovers and checks. No on-chain tx means it did not clear the vault.