Cold vaults isolate the signing environment from network-connected systems.
- Cold vault signing uses the same governance approval model as hot vault signing.
- The difference is transport: operations move between the online system and the air-gapped workstation as
.datfiles. - A cold bridge runs on the air-gapped workstation and provides the local interface that the vault polls for signing work.
- Accounts, transactions, and manifests created for a cold vault remain
Pendinguntil the signed payload is imported back into Ripple Custody. - Cold vault operations trade speed and automation for stronger physical isolation.
Cold storage reduces the attack surface for high-value assets because the signing environment is not reachable from the online deployment. Even if an online component is compromised, the attacker still cannot directly reach the cold vault signing environment.
For architects and operators: Cold vaults require operational discipline. You need an air-gapped workstation, controlled transfer media, clear verification steps before signing, and recovery procedures for the workstation, vault configuration, and KMS material.
Before using cold vaults, you should understand:
- Vaults - How vaults relate to KMS, accounts, and governance-approved signing.
- Transaction processing - How approved transactions move to signing and broadcast.
- Key management planning - How KMS choices affect signing and recovery.
A cold vault uses a physically isolated signing environment. The online deployment prepares operation payloads, an operator transfers those payloads to the air-gapped workstation, the cold bridge makes the payload available to the local vault, and the signed result is transferred back for import.
| Component | Role |
|---|---|
| Online Ripple Custody environment | Creates accounts, transactions, and manifests as governed operations. Exports pending cold vault operations. |
| Transfer media | Moves .dat payloads between the online environment and the air-gapped workstation. |
| Cold bridge | Runs on the air-gapped workstation. Provides the local UI and API used to upload, inspect, sign, and download operation payloads. |
| Vault | Polls the cold bridge for signing work, verifies the notary attestation, builds the transaction, and signs. |
| KMS | Protects the signing key material and performs cryptographic operations. |
Both vault types follow the same governance and approval process. They differ after the operation is prepared for vault signing.
| Factor | Hot vault | Cold vault |
|---|---|---|
| Connectivity | Network-connected. | Air-gapped. |
| Signing path | Vault polls the online API for operation queries. | Vault polls the local cold bridge for operation queries. |
| Operator involvement | Automated after approval. | Manual export, transfer, signing, and import. |
| Typical use | Frequent transactions, payments, and operational liquidity. | High-value reserves and cold storage. |
When a cold vault is first registered, it can appear in a Pending state because it cannot automatically connect to the online deployment. Complete the manual handshake before using the vault for accounts, transactions, or manifests.
At a high level:
- Register the cold vault using the standard vault registration flow.
- Download the vault data from the cold bridge on the air-gapped workstation.
- Transfer the
.datfile to the online environment. - Import the file into Ripple Custody.
- Verify that the vault status is
Completed.
For steps, see Process cold vault operations in the UI or Process cold vault operations with the API.
| Responsibility | Why it matters |
|---|---|
| Air-gap controls | The workstation must remain isolated from networks so signing cannot be reached remotely. |
| Transfer media controls | .dat files move between the online environment and the air-gapped workstation. Use approved media and handling procedures. |
| Payload verification | Operators should inspect operation details before allowing the cold vault to sign. |
| KMS recovery | Cold vault recovery depends on protected KMS material and vendor recovery procedures. |
| Configuration backup | Recovery requires the same vault configuration, including the vault UUID and public key. |
| Task | Page |
|---|---|
| Plan the air-gapped workstation | Cold vault workstation planning |
| Deploy the cold bridge | Deploy a cold bridge |
| Register, view, update, lock, or unlock vaults | Manage vaults |
| Process cold vault operations in the UI | Process cold vault operations in the UI |
| Process cold vault operations with the API | Process cold vault operations with the API |
| Recover cold vault operations after workstation loss | Recover a cold vault |