Resources Solutions
Request Demo
Resources Solutions
Request Demo
Resources
Learn about crypto private key security from experts in the field.
Storing Crypto Private Keys in Environment Variables is Dangerous: Use a TEE
Dec 30, 2025 Leif Elliott
Environment variables do not offer protection against a wide variety of common vulnerabilities. Trusted Execution Environments (TEEs) like AWS Nitro Enclaves provide cryptographic isolation that closes these attack vectors.
Frequently Asked Questions
What is xes.software? +
We are a security engineering firm specializing in self-custody infrastructure for digital assets. We employ industry standard technologies (e.g. TEEs, threshold cryptography) to meet your specific security model, regulatory framework, and operational needs.
Why does building digital asset custody infrastructure require expertise? +
Cryptographic keys are unforgiving, there is no recovery path. With a massive attack surface and an easy path to value theft, digital assets are a prime target for cybercrime. Keys must be generated, stored, and used in environments that are provably isolated from the rest of the system, including from your own infrastructure team. Command of technologies that solve these problems is a specialized skill.
What technologies does xes.software use to build secure custody systems? +
Our solutions are often built around AWS Nitro Enclaves, which provide cryptographically enforced memory and CPU isolation through cryptographic attestation. This ensures your keys are never exposed, even to us or our clients' own infrastructure teams. We layer this with encrypted key derivation, strict access controls, and hardened operational procedures. That said, we don't believe in one-size-fits-all security. Every engagement starts with a threat model specific to your organization. The right architecture depends on your assets, your team, your regulatory environment, and your risk tolerance. We then design around your actual attack surface rather than applying a generic template.
© 2026 xes.software LLC. All rights reserved.