Resources · Status
As of July 2, 2026. This page is updated by our operations team whenever any component's status changes, and every incident — however small — is recorded below.
Current status
The platform is monitored component by component, because "the site is up" is not the same claim as "transfers are settling." A component is marked degraded the moment our internal alerting fires — not when clients notice.
One property holds regardless of what this board shows: fund-moving systems fail closed. If any part of the approval or signing path is impaired, transfers queue and wait; they are never signed by a fallback path with weaker controls. Availability incidents can delay operations — they cannot bypass policy.
Uptime
Measured from external probes at one-minute resolution, April 3 – July 2, 2026. Scheduled maintenance windows count against these numbers — we do not exclude them.
We publish measured figures, not marketing figures. You will not see "five nines" on this page; you will see what the probes recorded.
Incident history
Every incident in the trailing 90 days, regardless of severity. In none of them were client assets at risk: keys never left MPC hardware isolation, no policy control was bypassed, and fund-moving systems failed closed as designed.
A deploy introduced a slow consumer in the webhook dispatch service, and the delivery queue backed up behind it. Deliveries were delayed by up to 40 minutes but none were lost — the queue is durable, and all events were delivered in order of creation once the deploy was rolled back at 14:51 UTC. Root cause: a missing timeout on an outbound HTTP call; the timeout is now enforced at the dispatcher level and queue depth alerting was tightened from 5 minutes of lag to 1.
During a scheduled database failover test, the replica promotion took longer than rehearsed and read endpoints (GET /v1/balances, GET /v1/statements) served p95 latencies around 4 seconds; a small fraction of requests returned 503 and succeeded on retry. Transfer processing was unaffected — signing infrastructure does not share this database. Root cause: connection pools were sized for steady state, not for the reconnect storm after promotion; pool warm-up is now staged.
Month-end statement generation halted on a reconciliation check: one client's ledger showed a mismatch against the on-chain attestation. The mismatch turned out to be a rounding-display defect in the report renderer, not in balances — but the pipeline is built to stop rather than publish an unreconciled statement, and it did. All statements were verified and published by 15:00 UTC, and the statement.available webhook fired as normal. We consider the halt correct behavior; the renderer defect was fixed the same day.
Maintenance
Maintenance that could affect availability is announced on this page and by email at least 7 days in advance, and is scheduled in low-traffic windows (typically Sunday 02:00–05:00 UTC).
Subscribe
Two ways to hear about status changes without watching this page: