Skip to content
Executive summary

Cold vaults isolate the signing environment from network-connected systems.

  • Cold vault signing uses the same governance approval model as hot vault signing.
  • The difference is transport: operations move between the online system and the air-gapped workstation as .dat files.
  • A cold bridge runs on the air-gapped workstation and provides the local interface that the vault polls for signing work.
  • Accounts, transactions, and manifests created for a cold vault remain Pending until the signed payload is imported back into Ripple Custody.
  • Cold vault operations trade speed and automation for stronger physical isolation.
Why this matters

Cold storage reduces the attack surface for high-value assets because the signing environment is not reachable from the online deployment. Even if an online component is compromised, the attacker still cannot directly reach the cold vault signing environment.

For architects and operators: Cold vaults require operational discipline. You need an air-gapped workstation, controlled transfer media, clear verification steps before signing, and recovery procedures for the workstation, vault configuration, and KMS material.

Prerequisites

Before using cold vaults, you should understand:

Cold vault architecture

A cold vault uses a physically isolated signing environment. The online deployment prepares operation payloads, an operator transfers those payloads to the air-gapped workstation, the cold bridge makes the payload available to the local vault, and the signed result is transferred back for import.

Air-gapped workstation

Manual transfer

Online Ripple Custody environment

UI or API

Core services

Unsigned .dat file

Signed .dat file

Cold bridge

Vault

KMS
HSM or MPC

Air-gapped workstation

Manual transfer

Online Ripple Custody environment

UI or API

Core services

Unsigned .dat file

Signed .dat file

Cold bridge

Vault

KMS
HSM or MPC

ComponentRole
Online Ripple Custody environmentCreates accounts, transactions, and manifests as governed operations. Exports pending cold vault operations.
Transfer mediaMoves .dat payloads between the online environment and the air-gapped workstation.
Cold bridgeRuns on the air-gapped workstation. Provides the local UI and API used to upload, inspect, sign, and download operation payloads.
VaultPolls the cold bridge for signing work, verifies the notary attestation, builds the transaction, and signs.
KMSProtects the signing key material and performs cryptographic operations.

Hot vaults and cold vaults

Both vault types follow the same governance and approval process. They differ after the operation is prepared for vault signing.

FactorHot vaultCold vault
ConnectivityNetwork-connected.Air-gapped.
Signing pathVault polls the online API for operation queries.Vault polls the local cold bridge for operation queries.
Operator involvementAutomated after approval.Manual export, transfer, signing, and import.
Typical useFrequent transactions, payments, and operational liquidity.High-value reserves and cold storage.

Signing workflow

VaultCold bridgeTransfer mediaOnline systemUserVaultCold bridgeTransfer mediaOnline systemUserSubmit and approve operationPrepare cold vault operationExport unsigned .dat fileTransfer to air-gapped workstationVault polls for signing workVerify notary attestation and signReturn signed payloadDownload signed .dat fileImport signed operationsContinue account, transaction, or manifest processing
VaultCold bridgeTransfer mediaOnline systemUserVaultCold bridgeTransfer mediaOnline systemUserSubmit and approve operationPrepare cold vault operationExport unsigned .dat fileTransfer to air-gapped workstationVault polls for signing workVerify notary attestation and signReturn signed payloadDownload signed .dat fileImport signed operationsContinue account, transaction, or manifest processing

First-time cold vault handshake

When a cold vault is first registered, it can appear in a Pending state because it cannot automatically connect to the online deployment. Complete the manual handshake before using the vault for accounts, transactions, or manifests.

At a high level:

  1. Register the cold vault using the standard vault registration flow.
  2. Download the vault data from the cold bridge on the air-gapped workstation.
  3. Transfer the .dat file to the online environment.
  4. Import the file into Ripple Custody.
  5. Verify that the vault status is Completed.

For steps, see Process cold vault operations in the UI or Process cold vault operations with the API.

Operational responsibilities

ResponsibilityWhy it matters
Air-gap controlsThe workstation must remain isolated from networks so signing cannot be reached remotely.
Transfer media controls.dat files move between the online environment and the air-gapped workstation. Use approved media and handling procedures.
Payload verificationOperators should inspect operation details before allowing the cold vault to sign.
KMS recoveryCold vault recovery depends on protected KMS material and vendor recovery procedures.
Configuration backupRecovery requires the same vault configuration, including the vault UUID and public key.

Next steps

TaskPage
Plan the air-gapped workstationCold vault workstation planning
Deploy the cold bridgeDeploy a cold bridge
Register, view, update, lock, or unlock vaultsManage vaults
Process cold vault operations in the UIProcess cold vault operations in the UI
Process cold vault operations with the APIProcess cold vault operations with the API
Recover cold vault operations after workstation lossRecover a cold vault