Skip to main content
Porto by Anchorage Digital is an institutional self-custody wallet built with the security and technology Anchorage Digital is best known for, enabling unmatched access to DeFi & Web3 and seamless integration with the Anchorage Digital platform.
You’re viewing Porto documentation — a distinct product from Anchorage Digital’s core custody platform. Go to Anchorage Digital docs →
This documentation is for Porto users only. Any external sharing beyond authorized Porto users requires approval from Anchorage Digital. For support, contact portohelp@anchorage.com.

About Porto by Anchorage Digital

Porto makes institutional self-custody simple, while ensuring assets are safeguarded using a robust security architecture.

Secure self-custody

World-class security with end-to-end cryptographic integrity, FIPS-140 policy and private key security, and hardware security modules (HSMs).

Broad Ethereum and Solana support

Transact and self-custody ERC and SPL tokens—with support for more Layer 1s coming soon.

Seamless smart contract interactions

Connect to dApps for staking, reward-claiming, governance voting, and more.

Device requirements

All users are required to have an iOS device running iOS 18 or later with Touch ID or Face ID enabled. The Porto security model leverages the secure enclave only found in the Apple device. During on-boarding, each device is tethered to our HSMs. Supported devices:
  • iPhone 8 or later with Face ID or Touch ID enabled
  • iPad 5th generation or later

On-boarding

Prior to on-boarding, all users should download the Porto by Anchorage Digital app by searching “Porto by Anchorage Digital” in the Apple App Store.
You may need to upgrade to the latest iOS software to download the app.
Porto recommends on-boarding with at least 3 users. There are two critical steps to secure your organization and complete on-boarding:
1

Download the organization recovery document

The organization recovery document is used to restore your access to Porto if all admin users lose access to all Porto-enrolled devices. Store it in a safe and redundant manner so that Anchorage Digital can help you use it to restore access to Porto.Unlike a seed phrase, this PDF is not sensitive material on its own—it is only relevant within Anchorage Digital’s security architecture.Anchorage Digital cannot restore your access if you lose your organization recovery document. As a best practice, we recommend sharing the document with the other admins on the account. Do not lose it!It can always be re-downloaded in the settings tab, under the header Recover access.We do not retain a copy of the document and we will never ask you to send us a copy of the document.
Porto cannot restore your access if you lose your organization recovery document.
2

Distribute the wallet recovery shares

Wallet recovery shares can be used decrypt and expose the private key of your one or more of your wallets. With the private key of a wallet you can access your funds outside of Porto. A single wallet recovery share is not sensitive on its own, but with 2 out of 3 shares, your wallets become accessible outside of Porto.During or after onboarding, you can distribute each share to a different team member to ensure they are kept separate and secure. Maintaining the separation and security of each wallet recovery share is crucial for safeguarding your wallets against unauthorized access.

Security model

Every product decision is informed by deep expertise in security. The result is a wallet that sets the standard for digital asset security.

No passwords

Porto forgoes the use of usernames and passwords, which are susceptible to fraud, impersonation, and abuse.

No emails or texts

Porto does not use emails or phone numbers, so attackers cannot gain access by triggering email or SMS-based account recovery.

No unauthorized devices

Only pre-approved devices may access an account.

Biometric authentication

Users can only unlock the app using Face ID or Touch ID. Sensitive operations always require biometric approval.

Authentication via hardware security modules

Once a transaction is fully approved by the organization’s team, it advances to our specialized hardware system to be processed within minutes.
  • Hardware security modules: Private keys are generated on air-gapped HSMs. The system signs transactions without ever exposing private keys.
  • Hardware-enforced logic: Custom logic verifies that each operation has a valid quorum of approvals. Transactions can process only if the quorum threshold is met.
  • High-security data centers: Porto HSMs are housed in secure data centers around the world.

How it works

The Porto transaction flow is designed to prove with certainty that a given transaction reflects an organization’s intent. Once all three steps are complete, Porto processes the transaction within minutes.
1

iOS biometrics

Sensitive operations require the user’s biometric approval using Face ID or Touch ID. Each user’s identity is tied to a unique and unforgeable cryptographic key, created and stored in the iOS device’s Secure Enclave, so only authorized devices can access the account.
2

Multi-user approval

Every transaction requires approval from a predefined number of users on the organization.
3

Hardware-enforced logic

HSMs process the transaction once quorum approval is met. The system signs transactions without ever exposing private keys.

Access and policies

User permission levels

The platform has three permission levels. Users can hold multiple roles, and each vault can have its own user access configuration.
  • Admin: Full access to perform administrative tasks, including the ability to create and modify policies, add and delete users, manage trusted destinations, and create and edit vaults.
  • Operator: Access to perform operations in a vault, including initiating and approving withdrawals.
  • View-only: View permissions to vaults and the ability to view balances.

Device-based account access

Vault overview

Users can take advantage of multi-asset vaults to organize assets in the Porto wallet. There is no limit on the number of vaults. Each vault must have a minimum of 3 members and a minimum quorum of 2 approvers. With those conditions met, quorum approval can be customized. The number of members and approvers may be influenced by factors like the use case for each vault—frequent or infrequent withdrawals—and the amount of value in the vault.

Customize and configure policies

  • Customize all permissions: Configure permission policies across the entire organization and specific to each vault, ensuring everyone has only the permissions needed.
  • Configure quorums and sub-quorums per vault: Set one vault’s quorum to require approvals from 2 of 9 members, and another’s to require approvals from 5 of 6 members. Designating a sub-quorum of required approvers is also an option.
  • Empower administrators: Unlike other users, administrators can—if approved by the necessary quorum—add and delete users, add and remove trusted destinations, create and edit vaults, and change organizational policies.
Quorum definitions:
  • Quorums: A group of users with permission to initiate and approve operations, such as default, governance, staking, or withdrawal operations.
  • Sub-quorums: Additional approval layers ensuring operations cannot proceed without a set number of approvals from designated members. Policies may have as many sub-quorums as needed.
For more details, see Creating a vault and Adding users.