The client share on machines you control — deployed by you
The server co-signer is a binary you deploy: Docker Compose or Helm, with PostgreSQL, SQLite or cloud-object storage for the share. It joins MPC ceremonies automatically as your mandatory third party — high-throughput signing where the client share never leaves your perimeter.
Share the Trust, Guard the Keys
Mobile co-signing is right for human authorisation and wrong for continuous operations. The server co-signer is the same client party as a binary you run: your own cloud, your own network, your own key share — participating in every signing ceremony without waiting for someone to wake up.
Runs wherever you run: your cloud, your Kubernetes, your compliance zone. Share persistence is your choice, and the process auto-joins signing sessions over authenticated channels once deployed.
What it takes to run your own signing party.
Get answers to commonly asked questions.
Same idea, different residence: this is the co-signer binary on your infrastructure with the share in your persistence layer — maximum control, slightly more ops.
The attacker gets one share of three — not a key. Reshare rotates it out; policies bound what it could ever have signed.
VPC yes — scoped with Enterprise deployment. It needs connectivity to join signing sessions, so fully air-gapped operation is not the model.

Deploy the trust boundary where your auditors want it.