Digital asset custody for banks, running inside your own walls
Offer secure digital asset services to your clients without building custody technology from scratch, and without handing your clients’ assets to an outside custodian.
No one moves funds alone
- The key is split from the start. Multi-party computation (MPC) creates each private key as separate shares, held by independent nodes. The whole key never exists.
- A threshold signs together. With threshold signatures (TSS), any m of the n nodes each produce a partial signature. Fewer than m cannot move funds.
- One ordinary signature. The partial signatures combine into one, which looks like any normal transaction on the blockchain.
Clients want digital assets. Custody is the hard part.
Banks already hold what this market needs most: client trust, a licence and existing relationships. What most lack is the custody technology underneath.
Whoever controls the private key controls the funds. A key held in one place is a single point of failure: a target for theft, a risk of insider misuse, and a liability that is hard to insure and hard to defend to a regulator.
You already give clients a bank account. Now give them a digital asset account: same bank, same brand, same regulator, a new asset class.
Why banks choose this platform
Every wallet’s private key is split into separate shares from the moment it is created. Moving funds requires several independent nodes to approve and sign together. The complete key never exists anywhere.
Security without a single point of failure
An attacker would have to break into several independent systems at the same time to move funds. Compromising one node, or the platform itself, is not enough.
Full control, fully self-hosted
Runs on your infrastructure with your own HSMs. Client assets are never held by an outside custodian.
Built for regulators and auditors
“Four eyes” and segregation of duties are enforced by the technology itself, and every sensitive action is recorded in a tamper-evident audit log.
Lower operational and insurance risk
No single key to lose, no single signer to compromise, and no single machine whose failure stops operations.
Your rules, enforced by the system
Spending limits and approved destination lists are enforced by the custody nodes themselves. No one can override them from outside.
Independent by design
The platform is not an exchange and does not trade. There is no conflict between holding client assets and trading them.
Faster time to market
Key generation, signing, wallet management, blockchain connectivity and audit are already built and working.
Fits your existing systems
One REST API connects the platform to your mobile app, online banking portal or back office.
From onboarding to a confirmed transaction
Onboard
The bank sets up its access to the platform and receives secure credentials for its systems.
Create vaults
Separate vaults for each business unit, desk, legal entity or end client. Each vault gets its own master key, split across the nodes.
Open wallets
Client wallets are created instantly under a vault. Balances and history are available through the API.
Move funds
A transaction is checked against the bank’s rules, signed jointly by independent nodes, sent to the blockchain and tracked until confirmed.
Throughout, the bank can freeze a wallet instantly for incident response, classify wallets as cold, warm or hot, and receive real-time notifications when transactions are sent.
Protection built into every layer
The same discipline banks already apply to card keys and HSMs, taken one step further: no single machine or person can ever move funds alone.
- The full key never existsKeys are created, stored and used in separate shares. No device ever holds the complete key.
- Hardware-protected sharesEach node has its own dedicated hardware security module (HSM). A stolen share is unreadable without it.
- Keeps running if a node failsSigning needs only a set number of the nodes, the threshold, so some nodes can be offline without stopping the business.
- Rules that cannot be bypassedTransaction limits and destination lists are enforced inside the custody nodes. The platform can request a transaction, but it cannot override the rules.
- Role-based accessAdministrators, operators and viewers each see and do only what their role allows.
- Tamper-evident audit trailEvery operation that touches key material is logged in a way that makes any alteration detectable.
- Private by designTransactions look like ordinary blockchain transactions. The bank’s security setup is not visible on the public blockchain.
What banks can do with it
Client digital asset accounts
Offer retail, private banking or corporate clients a digital asset account under the bank’s own brand, with each client segregated.
Institutional and treasury holdings
Manage the bank’s own digital asset positions under strict multi-party control.
Regulatory pilots
Run a controlled pilot or sandbox program with infrastructure that is secure and auditable from day one.
Tokenisation and reserves
The same model extends to reserve management and token issuance keys, where no single point of control matters most.
Available today, and what comes next
Delivered for installation in the bank’s own data centre or private cloud, integrated with the bank’s existing HSMs. Custody nodes can sit in separate locations or security zones, so no single site or team controls enough of the key to move funds.
Available today
- Bitcoin custody, end to end
- Vaults for segregating clients, desks and entities
- Instant wallet creation for standard Bitcoin address types
- Threshold signing with a configurable number of nodes and approvals
- Transaction sending and status tracking
- Balances, transaction history and fee estimates
- Wallet freeze and archive, cold, warm and hot tiers
- Transaction policy: spending limits and approved destinations
- User roles: administrator, operator, viewer
- White-label client app in the bank’s brand
- Real-time event notifications
- Tamper-evident audit log with integrity check
- REST API and a reference web console
On the roadmap
- Ethereum and Solana
- Multi-person approval workflows (m of n, dual control)
- Single sign-on and passkeys
- KYC and AML screening, fiat on- and off-ramp integrations
- SDKs, available on request
See it working, then scope a pilot
In a live session we create a vault, open a wallet, and send a transaction signed jointly by independent nodes and confirmed on the blockchain. From there, we define the scope of a pilot together.