Patent-pending authorization technology for institutional digital assets
Stop unauthorized digital-asset actions before they are signed.
Decern is a separate approval gate for custodians, stablecoin issuers, wallet platforms, and tokenized-asset operators. The exact action must be approved before protected signing can begin, and every approved action leaves a portable proof record anyone can verify.
Product stage: research prototype and design-partner recruiting. Bitcoin signet only, no real assets, no deployed customers. External cryptographic review is being arranged. Application-security review has not been completed.
The problem
A blockchain can accept a transaction your institution never properly authorized.
The chain sees a valid signature. It does not know whether a key was stolen, a coordinator changed the recipient, an old approval was reused, policy was bypassed, or the institution's authority had already changed.
Stolen in crypto during 2025.
Stolen in the Bybit attack.
Infrastructure and operational compromise caused a disproportionate share of major losses.
One control failure can move billions.
Decern does not claim to stop every theft. It is designed to reduce unauthorized paths inside the protected signing workflow and preserve independently checkable evidence when high-value actions occur.
How it works
Decern turns authorization into a prerequisite, not an after-the-fact log.
Freeze the exact action
Amount, recipient, network, fees, purpose, and policy are fixed before approval.
Verify current authority
Decern checks that the people and systems approving the action are still authorized under the current state.
Require post-quantum approval
Every protected signer checks the approval itself. Without a valid approval, signing cannot begin.
Prove execution matched approval
Decern creates a portable proof record connecting the approved action, participating signers, and final execution record.
No valid approval. No signing.
What is built
A working review candidate, not a concept.
Exact-action approval
The approval is tied to the specific transaction. Change the amount, recipient, fee, network, policy, or authority state and the approval fails.
Signer-side enforcement
Each protected signer verifies authorization before it can participate.
One-time approval
Expired, reused, or already-consumed approvals are refused.
Fresh authority
Old authority and stale signing material are rejected before signing.
Portable verification
A standalone verifier checks the supplied authorization and execution record without relying on a Decern-hosted dashboard.
Read this qualification
These results are internally reproducible and ready for independent review. They are not an external audit.
Proof Center
Do not take the claim on faith. Inspect the evidence.
A. Public signet evidence Historical deployed signet system
The July 2026 signet demonstration produced two publicly inspectable transactions. Anyone can verify them on a public explorer. Both are on Bitcoin signet, a public Bitcoin test network. No real assets were involved.
| Date | Signet transaction |
|---|---|
| July 12, 2026 | 0cd810955c54de6a0ae6a6ff1a938164ba1ddc47412f9d9aa87c0d15d69b6289 |
| July 14, 2026 | 4e9b7c7bd3dba1db05c7c8d4e7ce06718d3ac1fcc6adba74b28e7154c0487227 |
These transactions were produced by the earlier deployed signet build. They were not produced under the August pre-sign approval gate described below. Open the full public signet evidence page.
B. Latest review candidate Tested offline, not deployed
- Repository
- PriviNet1/decern
- Branch
- feature/pq-control-plane-v1
- Frozen commit
- 9a857bb0ac69e5fba93171803f9ea3e2aee8e2e8
- Source tree
- b7c7cd1a5bd68ba9eba3f1e47db21027dbb2d4e8
- Continuous integration
- GitHub Actions run 31375514035, passed
- Tests
- 258 workspace tests passed
- Scenarios
- 12 of 12 offline demonstration scenarios passed
- Negative scenarios
- 11 scenarios produced zero nonce attempts and zero broadcaster calls
- Status
- Review-only prototype. Not deployed. No real assets.
These are internal, reproducible engineering results. They are not an external audit.
C. Synthetic failure demonstration
Select a failure condition. This demonstration runs entirely in your browser using synthetic data. It reveals no secrets and makes no network call.
D. Verifier
A standalone verifier checks a supplied authorization and execution record using independently supplied expectations and anchors, without relying on a Decern-hosted dashboard. A sanitized sample proof artifact, verification instructions, and the documented limitations are provided with the review package. Repository access is granted separately and is not automatic.
On quantum, honestly
What Decern can and cannot protect against.
What Decern can do
- Require NIST-standard post-quantum approval before protected signing begins.
- Preserve authorization evidence with post-quantum signatures.
- Protect stored custody material with hybrid classical and post-quantum sealing.
- Apply stricter policy to exposed keys or migration transactions.
- Prepare the control plane for future post-quantum capable asset networks.
What Decern cannot do
- Change Bitcoin or another blockchain's consensus rules.
- Turn today's classical network signature into a post-quantum signature.
- Stop a quantum attacker who derives a network private key and signs completely outside Decern.
- Replace independent hosts, hardware security modules, human review, and secure operations.
Decern quantum-hardens the institutional control path. The blockchain's own signature system remains a separate risk until the network changes.
Beyond Bitcoin
Bitcoin signet is the first adapter. The product is the control plane.
The chain-agnostic core is the company. Per-chain binding modules are adapters. Designed for multiple digital-asset systems. Demonstrated today on Bitcoin signet.
Where this matters commercially
High-value stablecoin treasury transfers
Stablecoin minting and burning
Reserve movements
Tokenized securities and collateral
Privileged smart-contract actions
Contract administrator rotation, pause, freeze, or upgrade
The second adapter is selected with a design partner. Decern does not claim support for every blockchain today.
Where Decern fits
Existing platforms secure keys and enforce policy. Decern adds a separate, portable layer.
| Existing layer | What Decern adds |
|---|---|
| Multi-party computation and threshold custody | Separately keyed post-quantum approval before protected signing |
| Pre-sign policy engines | Every protected signer verifies the cryptographic approval set |
| Platform audit records | Portable authorization-to-execution evidence |
| Enclave and policy proofs | A link to the exact institutional action, authority state, and execution record |
| Vendor-hosted verification | Standalone verification outside the operating platform |
Decern is not trying to replace an existing custody platform, a bank custodian, or a hardware security module. It is designed to integrate with them as an independent authorization and proof layer.
Next step
Review the architecture and evidence package.
Intended for digital-asset custodians, stablecoin and tokenized-asset operators, wallet and hardware security module companies, applied cryptographers, and strategic investors.
Direct contact: Brad Listermann, brad@privinet.net