ChainIT Inc. has put its organizational multi-party computation (MPC) wallets into production, adding a transaction-specific approval process that requires a verified member to authorize an action before the wallet can create a signature. The system links ChainIT ID, the company’s passwordless identity product, to organizational wallet controls and is included in each organizational digital identity profile without an additional charge, according to ChainIT.
The rollout, available since Oct. 6, 2026, targets a longstanding custody problem for companies holding digital assets: separating the authority to approve a payment from the cryptographic mechanism that signs it. ChainIT’s design requires a member to prove their identity, demonstrate that they retain authority within the organization, and approve the precise transaction requested. An approval for one transfer cannot be reused for another, the company said.
ChainIT presented the system during TOKEN2049 Week in Singapore on Oct. 6 as part of its “Agentic Web3 Complete Commerce” architecture. Existing organizational wallets are being migrated from the prior model, while available functions and integrations depend on a particular deployment.
Approval is tied to a single requested transaction
Under ChainIT’s stated workflow, an authorized organizational member begins a transaction by completing biometric liveness verification and wallet authentication. The user then signs an operation-specific approval through a personal wallet identity.
The company said the liveness check is performed outside the signing enclaves, isolated computing environments used to handle the wallet’s sensitive cryptographic operations. A primary enclave then checks whether the approval was submitted by a registered organizational member and whether it corresponds to the requested action.
Before a signature can be generated, the primary enclave verifies three conditions: the approval remains valid, the member is still active in the organization, and the requested transaction exactly matches the approval. ChainIT said approvals expire after a short period and can be used only once.
That design is aimed at narrowing the damage from a compromised credential or device. A stolen personal authorization key, on its own, would not produce an organizational signature under the workflow described by ChainIT. The attacker would also need to satisfy the relevant authentication checks and obtain approval that matches the individual transaction being attempted.
The approach also differs from a wallet arrangement in which one credential carries broad, continuing authority over an organization’s funds. Each transfer is treated as a separate authorization event, potentially giving firms a more granular record of who approved an action and under what role.
Two enclaves hold separate signing shares
ChainIT said its organizational wallet uses two-party MPC signing, a method that divides control of a private signing key into separate cryptographic shares. Rather than reconstructing the entire private key in one place, the two parties jointly produce a standard Ethereum-compatible signature.
In ChainIT’s system, the two key shares are stored in separate AWS Nitro Enclaves. AWS describes Nitro Enclaves as isolated computing environments designed to process sensitive data separately from a broader cloud workload. ChainIT said both enclaves must participate for the wallet to sign a transaction and that persisted MPC key material is encrypted.
The company said neither MPC party can independently generate an organizational signature. The organizational signing shares remain in its enclave infrastructure rather than being stored on an individual member’s device.
A member’s personal authorization key is also separate from the organizational MPC shares, according to ChainIT. That separation places the employee or officer in the role of approving a specific instruction, while the enclave-based MPC process handles the organizational wallet signature only after its policy checks have been met.
The model would be particularly relevant for corporate treasuries, foundations, payment operations, and other entities where several people may have different levels of authority. A person may be entitled to request or approve a payment without possessing the technical capability to sign for the organization unilaterally.
Governance controls extend beyond payments
ChainIT said the wallet’s governance framework connects officer registration, assigned roles, authority levels, and an attested wallet policy. The same verified-authorization model applies to invitations and membership changes, according to the company.
That feature addresses a second risk in organizational custody: the ability to change who has signing privileges. Controls limited only to outgoing transfers can be weakened if an attacker or unauthorized insider can add a new approver, elevate an existing role, or alter the wallet’s policy. ChainIT said its framework is intended to govern both who can transact today and who can change permissions for later transactions.
The company has described the system as passwordless, using biometric liveness checks, device verification, and cryptographic proof of identity instead of a memorized account password or passphrase. One-time verification challenges remain part of relevant security workflows, ChainIT said.
Passwordless access does not eliminate authentication steps; it shifts them toward device-bound credentials, live-user checks, and cryptographic proofs. In an organizational setting, ChainIT’s addition is the policy layer that determines whether an authenticated person is authorized to act for the entity at that moment.
ChainIT seeks wider integrations
ChainIT said ChainIT ID can be used across supported ChainIT-enabled applications without requiring a separate password for each service. Each application keeps its own verification and authorization requirements, the company said.
The company is pursuing integrations with wallet providers, marketplaces, payment platforms, exchanges, and enterprise Web3 teams. Such integrations would determine how broadly the identity-and-approval flow can be used beyond ChainIT’s own products.
ChainIT also said its Web3 architecture is supported by 15 issued patents and that its technology supports treasury operations at major U.S. banks. Its platform includes ChainIT ID, organizational MPC wallets, Pactvera, and ChainIT Pay.
For organizations, the production launch places transaction authority alongside key security rather than treating MPC alone as a complete governance solution. Splitting signing shares can reduce reliance on a single private key, while ChainIT’s transaction-by-transaction approval process is designed to ensure that the entity’s current rules and an authorized human decision are checked before funds move.
For more on secure Web3 identity and wallets, explore Toobit Academy’s Web3 wallet security guide today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
