Who stands behind this Solana address?

An organization seal answers it: the company signs with the electronic signature it already holds, and applications check the seal

Try: Acme Robotics OÜ, EU · ТОО «Ромашка», Kazakhstan · unsealed wallet

Seal your wallet
Bp75o5N39Zs2Qz7xseSSHVEKT8yAw8YEVxTQ48ZBeALw

Live extract from Solana devnet: a demo company sealed through the test attestor

Problem

The wallet identity gap

A Solana wallet shows its full transaction history but not the legal counterparty behind it. Company identity and wallet control require additional evidence

So each platform runs its own onboarding and verification for business counterparties, and the result stays inside that platform

Rules for banks, payment providers and digital-asset service providers already ask who receives a transfer.[1][2][3][4] In Kazakhstan, licensed digital-asset providers must also check their customers[5][6]

  1. The FATF standard known as the Travel Rule requires virtual asset service providers to obtain and hold originator and beneficiary information on virtual asset transfers and to send it to the receiving providerSource: The FATF Recommendations, updated October 2025: Recommendation 16 and the Interpretive Note to Recommendation 15, paragraph 7(b) · fatf-gafi.org
  2. Since 30 December 2024, EU crypto-asset service providers must ensure that every crypto-asset transfer, whatever the amount, is accompanied by information on the originator and the beneficiary. For transfers above EUR 1,000 to or from a self-hosted wallet, they must take adequate measures to assess whether the wallet is owned or controlled by the originator (outgoing) or the beneficiary (incoming)Source: Regulation (EU) 2023/1113, Articles 14, 16 and 40 · eur-lex.europa.eu
  3. Since 9 October 2025, banks and payment providers in the euro area must check that the payee's name matches the IBAN before a euro credit transfer is authorised, and warn the payer if it does notSource: Regulation (EU) 2024/886, Article 5c of Regulation (EU) No 260/2012; European Commission news, 10 October 2025 · eur-lex.europa.eu · finance.ec.europa.eu
  4. Kazakhstani licensed digital-asset providers must collect and keep information on the sender and the recipient of digital-asset transfers. If that information is missing, they must suspend the operation and, if the client does not supply it, refuse itSource: Law of the Republic of Kazakhstan No. 193-VII on digital assets, Article 12-1, paragraphs 8 and 9 · adilet.zan.kz
  5. In Kazakhstan, organising trade in unsecured digital assets such as cryptocurrencies is permitted only through exchange operators and trading platforms licensed or registered by the National Bank, or through licensed participants of the Astana International Financial Centre (AIFC), with a few statutory exceptionsSource: Law of the Republic of Kazakhstan No. 193-VII on digital assets, Article 12-1, paragraph 1 · adilet.zan.kz · nationalbank.kz
  6. Under Kazakhstan's anti-money laundering law, digital-asset service providers, including crypto exchange operators, trading platforms and issuers of digital financial assets, are subjects of financial monitoring and must carry out customer due diligenceSource: Law of the Republic of Kazakhstan No. 191-IV, Kazakhstan's anti-money laundering law, Articles 3 and 5 · adilet.zan.kz

Sources checked on 3 October 2026. This is not legal advice

Use cases

Who it's for

Payment and asset platforms

Platforms that must verify business counterparties check the organization seal instead of running a separate onboarding for each company

Government reporting teams

Transfers between sealed wallets show the company on each side. We see the first pilot opportunity in the Alatau City ecosystem

Today
Declarations go through accounting and periodic reports
With MOR
Reporting reads transfers of a state-issued token between sealed wallets as they happen, with the company on each side

First users: corporate wallets with electronic signatures. Kazakhstan comes first, then compatible EU organization certificates

Alatau City: a planned scenario

Switch the ledger to see what a reporting team would see, with and without seals

Transfers of a state-issued token in Alatau City. Example data
DatePayerPayeeAmountPurpose
2027-03-02Bp75…eALw7kF3…9xQ248,000,000Office purchase, block 4
2027-03-023nVp…aL9e7kF3…9xQ252,500,000Office purchase, block 7
2027-03-037kF3…9xQ2DERF…5GmF1,200,000Building automation
2027-03-04DERF…5GmFBp75…eALw300,000Consulting
  1. 1

    The state issues a token that moves only to sealed wallets

  2. 2

    A verified company pays for a property. MOR checks the buyer and seller wallets

  3. 3

    The receipt feeds an authorized reporting integration

Planned scenario with example data.[7][8] Asset registries and reporting require integration with the city

  1. Kazakhstan has adopted a constitutional law on the special legal regime of Alatau City. It provides for its own regulation of digital assets, to be set by an act of the city administration agreed with the National Bank. The relevant articles take effect on 1 January 2027Source: Constitutional Law of the Republic of Kazakhstan No. 286-VIII of 8 May 2026 on the special legal regime of Alatau City, Articles 47 and 90 · adilet.zan.kz · akorda.kz
  2. Kazakhstan's president has described Alatau as the first crypto city in its part of the world and has announced plans for a CryptoCity pilot zone where cryptocurrencies could be used to pay for goods and services. These are announced plans, not rules in forceSource: Statements by the President of Kazakhstan at the meeting on the development of Alatau and at the Astana International Forum · akorda.kz · akorda.kz

Mechanism

How it works

  1. 1Sign

    The company signs a short request with its electronic signature: an NCA key in Kazakhstan or an organization certificate in the EU

    MOR-SEAL-REQUEST-V1
    program: Cqbw…P1aP
    address: Bp75…eALw
    kind: wallet
    controller: Bp75…eALw
  2. 2Verify

    An attestor checks a Kazakhstan signature off-chain, and the program verifies an EU certificate and signature on-chain

    { "name": "ТОО «Ромашка»",
      "trustService": "Gfmd…EFnJ",
      "identifierHash": "…",
      "signature": "…" }
  3. 3Register

    The wallet controller registers the seal: the company name and a salted hash of its BIN or registry number go on-chain

    seal 3iQx…fjaL
    name ТОО «Ромашка»
    jurisdiction KZ
    trust level attested
    valid until 30 Mar 2027
  4. 4Check

    Any Solana program can check the seal; the Token-2022 transfer hook checks it on every transfer

    Program 2A8c…khz2 failed:
    custom program error: 0x238c
    9100: recipient has no seal

Valid required seal: allow. Missing or expired seal: reject

let seal = mor_verify_seal::verify_seal(&seal_account, &owner, TrustLevel::Attestor)?;

One call from the mor-verify-seal crate, in any Solana program

Try the sealed transfer

For the city

Organization seals
Companies seal their wallets with the electronic signatures they already hold. Each seal shows its trust level and who confirmed it
Token rules
A Token-2022 transfer hook lets a state-issued token move only to wallets with a valid seal
Reporting from the ledger
Reporting teams read transfers between sealed wallets from the chain, instead of collecting periodic reports

Existing approaches and MOR

In Kazakhstan, individuals declare digital assets on tax forms 270.00 and 250.00, which ask for the exchange or wallet name and the wallet address[9]

The wallet address is already what the state asks for. MOR adds the company behind the address, confirmed by its electronic signature

ApproachIdentity sourceApplication accessMain dependency
Licensed exchangesCustomer onboardingExchange integrationLicensed operator
KYB platforms, e.g. SumsubDocuments and company registriesProvider APIVerification provider
Attestations, e.g. EASIssuer-defined claimsAttestation schemaAttestation issuer
MORElectronic signatures of organizationsSolana registry + Token-2022 hookTrusted CAs + Kazakhstan attestor

Reusable verification across Solana applications. The trust model stays explicit: accepted certificate authorities and attestors

  1. In Kazakhstan, resident individuals who own digital assets on 31 December declare them in the annual declaration of income and property (form 270.00), where they list the exchange or wallet and the wallet address. The one-time declaration of assets and liabilities (form 250.00) also has a section for digital assetsSource: Tax Code of the Republic of Kazakhstan No. 214-VIII, Articles 417 and 423; Order of the Minister of Finance No. 695 of 12 November 2025, forms 270.00 and 250.00 · adilet.zan.kz · adilet.zan.kz

Roadmap

Now: company-wallet registry and Token-2022 demo on Solana devnet

  1. Months 1 to 2

    Pilot discovery

    Interview public-sector and platform teams. Define reporting needs and regulatory scope

  2. Months 3 to 4

    Security and integration

    Improve revocation. Prepare audits and tests. Research ZK proofs for the planned privacy layer

  3. Months 5 to 6

    Mainnet readiness

    Prepare the mainnet launch. Complete the security review and required approvals. Run an approved pilot

Next product scope: individual users and additional jurisdictions

Targets depend on pilot access, regulatory requirements and security review

Team

Both founders study Information Systems at KBTU

David Torossyan

Technical co-founder

Cryptography and infrastructure. Security engineer at Gamma Technologies: PKCS#11, HSMs and key management

Telegram @dtorossyan

Abylaikhan Karsybayev

Product co-founder

Design and customer development. Startup and Web3 product focus

Telegram @ablStartup

Questions

Does any personal data go on-chain?

No. A seal holds company data only: the company name and sha256(salt, jurisdiction, BIN or registry number). The salt stays with the owner, and the registry does not record the person who signed for the company

Who can seal a wallet?

A company that holds an electronic signature. In Kazakhstan, its head or an employee with signing rights signs with an NCA key; in the EU, the company signs with a compatible organization certificate. The wallet controller then registers the seal

What happens to a transfer to an unsealed wallet?

The Token-2022 transfer hook rejects it. The same happens when the recipient's seal has expired or its trust level is below what the token requires. On this site the transfer fails simulation, so your wallet never asks you to sign

Which signatures are supported?

Kazakhstan: signatures made with NCA keys through NCALayer, checked off-chain by an attestor. EU: P-256 eIDAS certificates, with the certificate and signature verified by the program on-chain. The seal records the path as its trust level: Attested or On-chain

Is MOR live on mainnet?

Not yet. The registry and the demo token run on Solana devnet, and the certificate authority and attestor use public test keys, so anyone can mint such seals. Mainnet readiness is planned for months 5 to 6 of the roadmap