Your Keys.
Clean Books.
Your Keys.
Clean Books.
Companies don't run Bitcoin as real money because two walls stand in the way: wallets count signatures instead of authority, and no self-custody tool produces books an auditor will accept. Coinfidential removes both. Approve spends by rank, not headcount. Pay over a fast, private rail. And watch every approved spend post its own balanced, standards-compliant journal entry, reconciled to chain, without a custodian ever touching your coins.
WHY IT EXISTS
Every other tool solves custody or the books. Never both, never privately.


“Custody is solved. The books are not, and no subledger on the market assumes you hold your own keys.”
“Same headcount, different authority. Finance + Operator + Employee is rejected. CEO + CFO + Finance is accepted.”
5 pillars, one system
Hold · Approve · Pay · Close · Prove: nothing bolted on
3-way reconciliation
chain = subledger = GL, per asset per period, breaks flagged and never auto-fixed
Built on
How it works
Authority, not headcount
Your org has ranks. Your wallet shouldn't flatten them. HTSS and Birkhoff rank hierarchies enforce who approved a spend in the cryptography itself, not in a server that can be bypassed. Each vault carries its own group key, policy and members.
Private by default
Taproot makes a threshold spend look like an ordinary single signature, so your approval structure never leaks on-chain. Silent Payments kill address reuse, and change rotates to a fresh address no observer can cluster back to you.
Books that close themselves
A vault event runs the pipeline: classify, cost by lot, measure and impair, post a balanced journal entry, reconcile to chain, drop into an audit pack. Every line carries the transaction hash and the approving authority. ERP-importable, standards-switchable by config.
Bitcoin that’s operational and reportable, without giving up self-custody or privacy.

Early access to the first self-custodial treasury that closes its own books
Join the waitlistWhy teams are joining
No custodian, no exception
Key shares stay with your people and the backend never signs. There is no float, no AUM, and no account anyone can freeze. Non-custodial isn't a mode you switch on. It's the architecture.
Standards that survive the law changing
Classification and measurement are config-driven, with TIFRS, IFRS and US GAAP (ASU 2023-08) supported and cost, fair value and revaluation shadow-measured in parallel. When the rules move, you change a setting, not a system.
Audit without exposure
A read-only auditor role reads the Nostr feed and the append-only log, verifying everything, authorizing nothing. Your auditor gets a clean trail; the chain still shows an unclustered footprint.
Built for your size
Bitcoin companies, NGOs and foundations, open-source treasuries, student clubs, merchant teams. Multi-vault separation of duties works the same whether you're five people or fifty.

Join the waitlist

FAQ
A self-custodial Bitcoin treasury platform where an organization can hold, approve, pay, and account for Bitcoin in one private, audit-ready system. Custody with a native subledger built in, not bolted on.
No, and no. Key shares live with your people, the backend never signs, and there is no account anyone at Coinfidential can lock.
Multisig counts signatures. Coinfidential enforces authority. Three people can be rejected and three different people accepted at the same threshold, because rank is part of the signing policy, not a note in a policy document.
An approved spend automatically produces a balanced journal entry, costed at lot level, reconciled against the chain, and filed into an audit pack, with the approving authority carried on every line.
TIFRS, IFRS and US GAAP including ASU 2023-08, with Taiwan ARDF guidance covered. Classification and measurement are config-driven, so a change in the law is a settings switch.
Yes. Journal entries are ERP-importable (SAP, Oracle, NetSuite), and auditors get a read-only role that can verify everything without holding any spend authority.
No. Taproot makes a threshold spend look like an ordinary single-signature payment, and Silent Payments prevent address reuse, including for change.
Separation of duties. Ops, treasury, payroll and project funds each get their own group key, address, members, rank hierarchy, approval policy and subledger stream.
Signers can be reshared without moving funds, and no single lost share can lock you out of a vault. Recovery design is a first-class part of the product, not an afterthought.
Pricing is per organization and vault seat, with an enterprise tier and an optional accounting add-on. Waitlist members get pricing before general availability.
The core is open. The managed service, enterprise features and support are the paid layer, so you can verify what holds your keys.
We’re moving through security audits, subledger v1 and accounting-policy sign-off before pilots with NGOs, Bitcoin clubs and open-source treasuries. Waitlist members are invited first.
Yes. Tell us about your treasury in the form above. We’re prioritizing Bitcoin-native teams in weak-currency markets, where the need is sharpest.
Through our open-source repos, docs, and community channels. Enterprise customers get a dedicated support tier.


