Do not buy a "you hold the keys" story for the default service key. It is not true today.
Honest keysDefault service keyHardwareGnosis Safe
The default JIL Wallet key is a service key. You sign in, you authorize every transaction, and JIL retains the ability to refuse or delay a sign that has not happened yet. The live signing path still reconstructs a secret server-side (reconstruct-and-sign). You do not hold a signing shard on that default path.
That is not classic self-custody. It is also not an exchange omnibus that can reverse a committed sign or freeze the bag by subpoena-theater. Those are different failure modes. This page names the one that is actually live.
Threshold ECDSA (FROST/GG20 class) is the destination. Until it ships, any page that says "no single party can sign" or "you hold a shard" about the default key is selling the roadmap as the present.
Search "non-custodial wallet" and you get a promise the live default key does not keep. Honest copy is how you keep a board, an auditor, and a regulator from treating the vault as a lie.
The compensating controls are real: you authorize, policy can refuse an unsigned request, hardware wallets pair, Gnosis Safe multi-owner treasuries exist. They are not the same as a user-held shard on the default key.
Use a hardware wallet or a Gnosis Safe when you need key control that is not the default service key. The Command surface is where that status should stay visible, not buried in a footnote.
JIL Federation Technologies, Inc. operates this wallet and the L1. It does not get to claim a user shard that the signer does not implement.
Proof of those records can settle on the JIL Layer-1 at jilsovereign.net. The L1 and this wallet are the same operating company: JIL Federation Technologies, Inc. Payment integrity and CREB are a sister company, JIL Sovereign Technologies, Inc. at jilsovereign.com.
Free to hold. Wrap to protect. You authorize every sign. Proof you can show.
The destination is non-custodial threshold signing. The live default key is not. Hardware and Safe paths are the current ways you control keys. Do not treat the default path as "your keys, your crypto."
The product still requires your authorization for a sign, and can refuse an unsigned request. That is not the same as a mathematical guarantee that JIL cannot sign alone. This page will not pretend otherwise while reconstruct-and-sign is live.
Sealed records can settle on the JIL L1 at jilsovereign.net. Same company: JIL Federation Technologies, Inc. Payment integrity is a sister company at jilsovereign.com.
Pair hardware or open a Safe before you tell anyone you hold the keys. Product paths: wallet.getjil.com, Command, Wrap, Gnosis Safe.
JIL Federation Technologies, Inc. operates getjil.com, the same company as the L1 at jilsovereign.net.