Architecture
Your mandate, on-chain.
Built so an agent can run a tokenised asset mandate and never move capital on its own. Six design facts separate infrastructure built for agents from an AI feature: the agent can only produce proposals; the mandate is enforced by the contract, not by a prompt; the custodian owns the key; a refused proposal is a first-class event; every run is traced to the ledger; models are interchangeable by design.
Custodian and account
What the custodian does. What the account does.
Your custodian is built to safeguard. The Brava account is built to act. You need both, and until now you only had one.
| Your custodian | The Brava account | |
|---|---|---|
| Purpose | Hold assets and keys securely. Refuse anything not on the list. | Execute a mandate. Do everything on the list, and nothing else. |
| Unit | The institution's vaults and keys. | One contract per client or entity, each with its own mandate. |
| Rules | Allowlists, limits and quorums, set at corporate level. | The client's investment mandate, in code, changed only by approval. |
| Capabilities | Hold, transfer, sign. Sometimes trade and stake through the custodian's own integrations. | Yield, credit, tokenised funds, real-world assets, treasury operations, portfolios across many clients, and what the market adds next. |
| Adding one | A new integration and a change to the custodian's risk model. | A mandate change, approved and enforced the same day. |
| Intelligence | None, by design. It does not know what an asset is worth or whether it can be exited. | Continuous data on backing, control, yield and exit routes, plus external datasets bought per call with provenance. AI research and preparation against the mandate. Live checks before every action. |
| Verifiability | Internal to the custodian. | Built on the Safe standard; contracts audited by Sigma Prime; deployed permissions checkable by anyone in the Security Screener. |
| Built for | People and processes. | Agents, with people approving. |
| Reporting | Balances and movements. | Positions, mandate compliance, approvals and the reasoning behind each transaction, from one ledger. |
The custodian decides what enters the account. The account decides what the capital may do. Brava supplies the data and the intelligence that make the second decision a good one.
The harness
What the agent sees, remembers, may do, and may delegate.
Sees
This account's mandate and version, positions, custodian envelope, eligible markets and relevant skills, loaded per task. The model never has to know the institution; the harness tells it.
Remembers
The account's ledger. Every proposal, refusal, approval and execution, read at the start of a run and written at the end. The audit trail is the memory.
May do
Prepare, check, execute through the custodian's permissions, report. Bounded to the mandate. Data purchases capped per account and logged.
May delegate
One agent per account, thousands of accounts per institution, one strategy across all of them. The institution supervises; the custodian holds the keys.
Skills
Written domain judgement the agent runs with: venue diligence, exit-path analysis, collateral tracing, mandate templates by jurisdiction, rebalance playbooks, failure handling. Versioned, tested, owned by the institution.
Evaluations
For every skill and mandate: proposals that must be refused, proposals that must pass, regression on every model swap.
The model is interchangeable. The harness is where your institution's requirements live. Skills are portable files; rights to customer-specific skills follow the agreed contract.
Own. Already running an AI orchestrator for the rest of the firm - Claude for Financial Advisors, or your own platform? Brava accepts proposals from any of them, including third-party research harnesses, and governs them all identically: mandate check, live risk checks, signature. The orchestrator thinks; Brava is the system where it is allowed to act on-chain. The two projects share one answer for your risk committee: nothing moves on-chain outside the mandate, whatever proposed it.
Separation of duties
Three roles, kept separate.
Your custodian safeguards the assets, holds each account's owner key and approves the policy envelope it may operate within. Your institution holds investment authority and sets each mandate with the client. Technical signing follows the permissions your custodian has configured. None of the three is asked to do the others' job. Approval granularity is configured per institution.
Inside the account, the mandate decides what can happen: venues, assets, exposure and concentration limits, exit requirements. A transaction outside it cannot execute, whatever proposed it. Live checks on price, protocol status and threat intelligence run before approval and hold the transaction if anything fails. Every executed transaction is recorded on chain and matched to the approval and the proposal that led to it.
Open, audited, verifiable
Built on Safe. Audited. Verifiable.
The account is a Safe smart account
The open smart account standard, audited, on more than 200 networks, holding tens of billions of dollars, with over 63 million accounts created and nearly 130 million transactions in Q2 2026 (figures from the Safe Ecosystem Foundation Q2 2026 report; confirm against the current report before citing). The standard your risk committee can check for itself.
Your assets do not depend on Brava's availability
Assets sit in Safe smart accounts under your custodian's key, which you can operate directly. Brava's services - research, automation, reporting - would need replacement or manual operation if Brava were unavailable; source code escrow and documented handover are part of every deployment, and deployed permissions are verifiable by anyone in the Security Screener.
Brava is the platform on top
We integrate and support the Safe standard inside a regulated institution and add what is not on-chain: mandate and control, data, AI over MCP, reporting, and the team that forward-deploys it. Smart contracts audited by Sigma Prime; the audit report, with component, version and scope, is in the diligence pack.
Modules and connectors
Platform modules and connectors.
Brava's platform is the five modules you license: Accounts, Mandate and control, MCP and skills, Intelligence, Reporting and record. Everything your accounts reach is a connector - a supplier you choose, added by configuration and onboarding, never by a change to the platform.
Custody
The custodian you already use, or a supported one - Fireblocks, Utila, MPC Vault, Ledger; Copper, Zodia, Standard Crypto. Each verified for how it approves the mandate envelope.
Markets
Yield venues, tokenised funds and real-world asset issuers, on-chain credit, stablecoins and rails - Aave, Morpho, Uniswap, Ondo, Securitize, Maple and the fund managers themselves. Onboarded venue by venue.
Strategies
Licensed indices and baskets, rebalanced by agents inside each mandate, reported against the benchmark. Providers named as licences are signed.
Data
Bought per decision through the Intelligence module, with provenance and a spend cap per account: Glassnode, Arkham, Nansen, Alchemy, Messari, Cambrian, CoinMarketCap, The Graph.
AI
Your models on your keys, in the orchestrator you already use - Claude for Financial Advisors, Claude, ChatGPT, Codex, Cursor, any MCP client - or your own agent platform. To the orchestrator, Brava is a connector and a skill set: accounts, mandates, eligibility, execution and the record, exposed over MCP.
Capabilities
Stablecoin yield
Idle stablecoins into tokenised money market funds and allowlisted vaults, exit routes verified before entry, yield reported net of fees.
On-chain credit
Lend and borrow against the account's own collateral inside mandate limits, liquidation risk monitored continuously.
Tokenised funds
Subscribe, hold and redeem tokenised treasuries and funds, eligibility checked per account.
Real-world assets
Private credit, equities and funds as tokenised venues come on. Brava coordinates integration; you complete the venue's KYC.
Treasury operations
Operational cash allocated against liquidity requirements, reviewed by agents on your schedule, signed by your team.
Client portfolios
One strategy across every client account, each inside its own mandate and custody arrangement, each with its own approval record and statement.
Indices and baskets
Let each account follow a licensed digital asset index or basket, rebalanced by agents inside the client's mandate, performance reported against the benchmark.
Authority and control
Which conditions live where.
On-chain
Enforced by the account contract and its modules: allowlisted venues and contracts, the owner key with the custodian, module permissions. The exact on-chain conditions are listed in the diligence pack.
Pre-trade checks
Run by the control plane before a proposal is prepared: concentration and liquidity limits, exit depth, price and protocol status, threat intelligence. A failed or stale check holds the proposal.
Human approval
Required for every executed instruction and every mandate change, at the tier your policy sets. Grouped approvals only where policy permits. Recorded individually.
Monitoring
Continuous: venue status, depegs, limit approaches, reconciliation breaks. Alerts propose; they do not act.
Mandate changes and administration
Mandate changes follow transaction-grade approvals with version history and custodian sign-off of the envelope. Who holds account upgrade and administrative powers, and how they are exercised, is set out in the diligence pack.
The signature
The only event that moves capital. Follows the permissions your custodian configured. Brava cannot produce it.
Data and AI governance
What models see, where they run, what is logged.
What models see
Per task: the account's mandate and version, positions, custodian envelope, eligible markets and relevant skills. Client identities are not required for research or preparation and are not sent to models unless your deployment requires it.
Deployment modes
Default: your keys, Brava-hosted runtime with regional residency. On request: the same open artefact installed in your cloud. Also available: Brava-run models under enterprise zero-retention terms. Standard and separately scoped modes are confirmed at assessment.
Data classes
Client data stays in your environment or a dedicated tenant with residency in your jurisdiction and is never used for training. Market data is Brava's and its partners', served with provenance. On-chain data is public by nature and pseudonymous by design; the ledger does not contain client identity.
Logging
Every model call, skill version, data source and approval is recorded for your model-risk process and exportable.
Continuity and exceptions
What happens when something is unavailable.
If Brava is unavailable
Assets remain under your custodian's key in Safe smart accounts you can operate directly. Research, automation and reporting services would need replacement or manual operation. Source code escrow and documented handover are part of every deployment.
If a model is unavailable
Scheduled runs fail safe: nothing is prepared, the miss is recorded and alerted, and another supported model can be substituted under the same skills and evaluations.
If a data source or integration is unavailable
Checks that depend on it hold proposals rather than pass them; the record shows which source was missing.
Reconciliation breaks
Raised as exceptions with a drafted cause, routed to your operations team, and closed with a recorded resolution. Your administrator's books remain the books.
Supported scope
Connector catalogue and supported scope.
Every connector in custody, markets, strategies, data and AI, and every platform module, is maintained with product status and deployment dependencies kept separately: per custodian, the integration work required and confirmation that mandate approval satisfies its policy; per network, indexing coverage and depth; per venue, research coverage, execution status and onboarding dependencies; per entity type and jurisdiction, KYC requirements.
The current catalogue, licensed platform scope, engineering scope, ongoing support and customer responsibilities are confirmed with your team at assessment and detailed in the engagement documents.
Security and due diligence
The diligence pack.
Key management and account architecture. Sigma Prime audit reports with component, version and scope. Source code escrow terms. Penetration testing and certification status. Model governance: model-agnostic interface, all outputs and approvals logged. Data residency, including where inference runs and retention policy. Regulatory mapping for Cayman, Switzerland, the UK, the EU and the US.
Your mandate, on-chain.
Talk to us about an assessment for your institution.