0.00 s

The boot screen, drawn live from a port of firmware/bootart.py. One frame every 30 ms, as on the Pico. The status line is the emulator's example sequence.

Brand guide · v1 · October 2026

PicoQuorum

A physical approval device for Safe multisig wallets. Several people, several keys, one Safe.

Everything here comes from the boot screen: five owners, three of them sign, and their green triangle turns into the Ethereum diamond. The name, the mark, the colours and the motion all follow from that one picture.

Name

One word

Pico for the Raspberry Pi Pico it runs on. Quorum for the idea at its centre: a Safe needs a set number of owners to agree before anything moves. The multisig is the star, and the name says so.

PicoQuorum

One word, two capitals. Set in Atkinson Hyperlegible Next Bold. The capitals are highlighted here only to show where they go.

Write
  • PicoQuorum
  • the PicoQuorum console · the box with the screen
  • a PicoQuorum key · the plug-in secure element
Never
  • Pico Quorum Picoquorum PICOQUORUM PQ
Mark

Three of five

The boot screen in miniature. Five owners sit evenly on a circle. The top owner and the two at the bottom have signed: they are green, and the triangle between them is filled. The two who didn't sign stay amber and smaller. It reads as a quorum, a tall triangle and a small person, depending on how far away you are.

On night
On paper

Geometry

Points
5, at −90° + 72°·k on a circle of radius r
Signed
Top, lower left, lower right. Dot radius r/4
Waiting
Upper left and right. Dot radius r/6
Triangle
Joins the three signed centres, filled with face green at 55%
Order
Top signs first, then left, then right (as in the animation)

Lockup

PicoQuorum

On the panel the name is 26 px bold; the ring radius is 12 px and the mark's centre sits 13 px in from the left edge, with the word starting at 34 px. Scale those proportions. The mark always goes on the left, centred on the word.

Smallest use: 16 px, where the waiting dots shrink to a pixel and a half. Below that, use the green triangle on its own.

Colour

Every colour means something

Six colours carry the brand, and each one has a job. Amber is an owner who could sign. Green is a signature, or anything else that is done and good. Ether blue is the network. The rest are neutrals for reading. The panel is dark first; the light values are the console's light theme.

Hex and RGB come from firmware/quorum_ui.py. The 565 value is what the Pico sends down the wire to its 16-bit panel.

Shading ramps

The diamond and the quorum's face are lit from the upper left. Each face's colour is picked along one of these ramps by how much it faces the light. Green fills the triangle at the marked point.

Diamond · #1E245C#DAE2FF
Quorum face · #006024face green#78FF96

Outside the brand

Reject red

The Reject button and anything that can't be undone. A red page is red all over. Never decorative.

Stake cyan

The thing at stake on a red page: the address that gains power, the amount. The only non-red there.

Type

Made for comparing

The console's job is to make people compare addresses and hashes before they sign. Atkinson Hyperlegible, from the Braille Institute, was drawn to keep look-alike characters apart. Next sets words; Mono sets addresses, hashes and the verify code. Both are SIL Open Font License.

PicoQuorum
Il1| O0o rn m 5S 8B 6b
Il1| O0o rn m 5S 8B 6b

Capital I, lower-case l and the digit 1 are three different shapes in both. So are O and 0.

The seven sizes

The firmware renders exactly these, shown here at the panel's own pixel sizes. Don't add an eighth.

bold26Headlines · Bold 26Send 0.05 ETH
bold18Titles · Bold 18Add a new owner
bold14Labels · Bold 14Family Safe · 3 of 5
sans14Body · Regular 14Nothing signs unseen
sans12Captions · Regular 12Nonce 42 · proposed 2 hours ago
mono13Addresses · Mono 500 130x5aAeb6053F3E94C9b9A09f33669435E7Ef1BeAed
monob28Verify code · Mono 700 283f9a c217

Open question: docs/quorum-ui/v2/FONTS.md compares five other sets for the words (Inter with its I/l alternates is the current suggestion). Atkinson Mono stays for addresses either way.

Motion

One clock, never stopped

The boot animation tells the brand's story in five beats. Each still below is a real frame; select one to jump the device above to it.

  • Nothing freezes

    Every frame is a function of one clock. While a boot step takes its time, waiting owners keep breathing and the diamond keeps turning.

  • Fade through the dark

    The panel has no transparency. A fade is a colour mix toward the background, so things arrive through their own dark shade.

  • Fill from the bottom

    Green pours up into the triangle with a bright surface line, then swells once in a soft glow. No flashes.

  • Land corner-forward

    The diamond's spin slows into 45° + 90°·n, its logo pose. A square pyramid repeats every 90°, so it can spin as long as boot takes.

Ease out

1 − (1 − t)³. Arrivals: owners landing, lines drawing, signing rings.

Smoothstep

t²(3 − 2t). Changes of state: the fill, the turn, the name and taglines.

MomentFrameTime
Voice

Plain and calm

A signing device should sound like a careful colleague. Short sentences, plain words, no hype. Talk about owners, keys and the Safe, the things people can point at.

Status line
Checking the chip…
Chip verified
Family Safe · 3 of 5
Taglines Draft
  • Your keys, your quorum
  • Nothing signs unseen
  • Hardware approvals for Safe
  • Every hash checked here
  • Joining Wi-Fi…Chip verified

    A step in progress ends in an ellipsis and sits in slate beside a spinner. When it's done, the ellipsis goes, the text turns white and a green check appears.

  • 3 of 5  3/5

    Write counts out. "3 of 5" reads the same aloud as it does on screen.

  • Family Safe · 3 of 5

    A middle dot separates facts on one line. No pipes, no slashes.

  • Ready  Ready!

    Sentence case, no exclamation marks. Money is moving; the device stays even-tempered.

  • SignReject

    Buttons say exactly what they do, one verb each. Sign is green and guarded; Reject is red and easy.