Spent a good part of the summer with this construction. Two choices deserve more credit than vault discussions usually give them: the operational delay is enforced twice by independent actors (client-side nLockTime plus the CS refusing short delays), and expiry is a scheduled rotation rather than a risk that silently ages. Disclosure: Custody Agents co-published an article with the BitVault team yesterday using B-SSL as the vault-layer case study, with Francesco and Riccardo reviewing those sections.
What the whitepaper deliberately leaves unspecified is the transport, and with a MuSig2 aggregate on the operational keypath that question is sharper than it looks: every spend moves nonce and partial-signature rounds over something that must never induce nonce reuse. Those are transport questions, so they have their own thread:
One construction question for here: the 350-day refresh is CS-driven; if the CS is gone, does the client keep its own schedule, or does the fallback path simply mature?