Skip to main content

MPC Hot Signer

Automated transaction signing

In Bron, every outgoing transaction — whether it's an external send or an internal transfer — must be signed by a team member who holds both the required permissions and key shards. This ensures security, but it also introduces operational delays:

  • The signer must be available in person,

  • And manual approval takes time, especially across time zones or during off-hours.

For some businesses, this manual signing process leads to unacceptable operational overhead. Others require full automation of trusted transactions.

Hot Signer is a secure software solution provided by Bron that you install and run on your own infrastructure (e.g. cloud or private server). Once set up, it automatically signs transactions via API — no manual involvement required.

How It Works

  • You deploy Hot Signer inside an isolated Docker container on your infrastructure.

  • The signing shards are encrypted by key stored in your cloud provider’s Key Management System (KMS).

  • A Bron team member with "owner" permissions and access to the shards can securely share them into the Hot Signer container after deployment.

  • Once set up, Hot Signer can sign transactions automatically.

Note: Only users with owner rights and access to shards can provision Hot Signer.

Security Considerations

While Hot Signer is designed with strong isolation and encryption, Bron does not control how it is installed or maintained on your infrastructure. Its security ultimately depends on your deployment practices.

We strongly recommend working with your DevOps or security team, and reaching out to us for guidance if needed.

Technical Setup

Full technical documentation is available here: Hot Signer API & Deployment Guide

If Hot Signer Loses Access to Its Shards

Deleting the KMS key that encrypts Hot Signer's shards — or losing the container's database — makes that copy of the shards unreadable, and reinitialising Hot Signer requires a fresh database and new keys.

This does not put your funds at risk, and it does not lock the accounts Hot Signer was signing for.

  • Hot Signer holds a copy of your own shard (Shard 1) — the same shard your trusted devices hold. Losing that copy does not lose the shard.

  • Every other trusted device in the workspace keeps signing for those accounts as normal, through the desktop, web or mobile app.

  • Even if no copy of your shard were left anywhere, the signing key is still recoverable: two of the three shards rebuild the third, so Bron's shard and the Trusted Third Party's shard can rebuild a lost device shard. See MPC Security.

How to restore automated signing

Deploy a fresh Hot Signer, then have an Owner with access to the shards share them into the new container — the same step used to provision Hot Signer the first time. There is no security delay and no recovery flow involved.

⚠️ Do not use FaceScan, Guardian or self-recovery to bring a Hot Signer back while your team still has working trusted devices. Those flows remove every other trusted device — afterwards only the newly recovered device can sign. They exist for the case where no trusted device is left at all; see Access Recovery.

If you have questions, contact our support team via messenger on the Bron platform or by email support@bron.org.

📅 Questions about how this works for your team? Book a call with our product team

Did this answer your question?