Short answer
AERSeal is an AERKey-powered service for placing a smart contract's privileged administrative powers under threshold custody. It is identified as part of the AER360 family, but it is not listed as one of AER360's four pillars.
This is not retail token custody and it is not a bridge. The existing contract stays at the same address. The client uses its own wallet to transfer ownership, upgrade, minting, or governance powers to an AERKey-derived threshold address. Later privileged actions follow the registered approval policy.
AERSeal at a glance
The published seven-step custody workflow
- Open an account. Complete KYC or KYB, define policy, and register a passkey.
- Register the contract. AERSeal identifies every privileged power and refuses partial custody.
- Verify the threshold address. Address derivation and a signed fresh challenge are made available for independent checking.
- Transfer authority. The owner transfers powers using their own wallet; AERSeal says it never asks for or sees the original key.
- Prove completeness. The service checks the transfer on-chain. A forgotten privileged role keeps the custody pending.
- Activate custody. The annual term begins when custody becomes active.
- Operate under policy. Mint, upgrade, and other privileged requests are proposed exactly, approved by signatories, signed by the cluster, and executed.
Currently presented chains and contract shapes
The public transfer interface currently shows Aeredium and Ethereum as enabled choices. It recognizes four contract structures:
- Single owner: contracts following an Ownable-style owner model.
- Stablecoin: Circle FiatToken-family contracts.
- Role-based suite: AccessController-style contracts with multiple privileged roles.
- Signer-set governance: contracts matching the Governed pattern.
AERSeal says a contract that matches none of these structures is refused. It also says it will not onboard only part of a contract's privileged surface. This is current interface support, not a guarantee that every implementation or proxy pattern will pass registration.
Account-bound identity and recovery
The account flow combines identity verification, a policy interview, and a passkey. Individuals complete KYC and organizations complete KYB through AERKYC. The service sends a personal account-bound verification link after the email address is confirmed.
AERSeal says this service will not use a general public KYC link because the result must be bound to the account. Identity is also part of the recovery process if a device is lost. The terms say recovery follows the original onboarding policy and may require re-verification and the applicable approval quorum.
How governed operations work
Signatories are registered by email and receive personal proposal links. The transfer page currently describes a two-approval workflow and recommends registering at least three signatories. The contractual policy remains the controlling source for a particular custody.
Once the original owner transfers a power, the old private key no longer controls it. A later mint, upgrade, ownership transfer, or other privileged action must be proposed through the service, approved under policy, and signed by the threshold cluster.
Offline verification is a meaningful public control
The verifier runs on the user's device and accepts a group public key, threshold address, fresh 32-byte challenge, and 65-byte signature. AERSeal says the check does not require trust in a stored record or its server and also offers a live demonstration.
This tool verifies the published relationship between the threshold key, address, challenge, and signature. It does not by itself audit the full custody service, enclave implementation, policy engine, or operational security.
Commercial and operating model
- Service entry is invitation-only after successful verification.
- Plans and pricing are shown privately in the member portal.
- The subscription is prepaid and renews annually unless cancelled under the published notice period.
- Executed threshold signatures consume signature credit; a failed delivery is described as refunding the draw.
- On-chain gas comes from the custody's own gas balance and is separate from Aeredium's service fee.
- Public support is listed as 360support@aeredium.io.
The expiry risk must be understood before transferring control
The published terms make this the most consequential operational risk: cancellation does not immediately restore the original owner. Custody continues through the paid term, and the client must complete a final governed transfer to an address it controls before expiry.
After expiry, Aeredium says it no longer operates the threshold key. If contract powers remain assigned to that address, those powers can become permanently inoperable, with no reinstatement. The terms also place responsibility for policy contacts, contract logic, chain behavior, and adequate gas on the client and cap Aeredium's liability.
What the public launch establishes
Operational service surface
Overview, account, transfer, member custody, offline verifier, terms, cookies, and support routes are publicly reachable.
Security properties
CGGMP24 threshold signing, hardware-attested enclaves, complete-key elimination, policy enforcement, and on-chain custody evidence are Aeredium's own claims.
Adoption and economics
No named customers, custody count, assets or contracts secured, executed-signature volume, public plans, or revenue data were identified.
Primary sources
AERSeal overview
Purpose, seven-step workflow, invitation model, and AER360 relationship.
Account and transfer
KYC/KYB, passkey, policy, supported chains, contract structures, and signatory workflow.
Offline verifier
Device-local threshold-address challenge and signature verification.
Terms and cookie policy
Provider, subscription, signature credits, gas, expiry, recovery, liability, and first-party cookie disclosures.
Frequently asked questions
Does AERSeal take the original private key?
No, according to its public workflow. The owner transfers contract powers from their own wallet, and AERSeal says it never sees or requests the original key.
Does the smart contract move?
No. The contract remains at its existing address; its privileged roles are reassigned.
Is AERSeal open to everyone?
The public site is accessible, but service onboarding is invitation-only and pricing is private.
What happens at the end of custody?
The client must execute a final governed transfer before expiry. Leaving powers assigned after threshold signing expires can make them permanently inoperable under the published terms.