Key custody

Wallet and custody engineering,
keys you can prove.

We design and build wallet systems for crypto startups, licensed VASPs and banks. One EU team owns key generation, signing policy, sweeps and the audit trail. The result is custody your ops team can run and your auditor can read.

  • EU-based engineers
  • MiCA-ready architecture
  • AML and Travel Rule aware

Key tiers

Three tiers, one policy

Splitting funds by tier is the oldest custody control there is. It still works. Each tier holds a different amount and answers to a different rule.

Trading balances sit next door in our exchange build practice.

  • Hot tier

    Holds
    Working float
    Signing
    Automated, policy-bound
    Approval
    Rules only

    Customer withdrawals and venue settlement.

  • Warm tier

    Holds
    Daily top-up
    Signing
    MPC quorum
    Approval
    Two named people

    Refills the hot tier on a set schedule.

  • Cold tier

    Holds
    Reserve
    Signing
    HSM, offline
    Approval
    Quorum plus dual control

    Long-term storage. Moved rarely, never in a hurry.

Scope

What we build around the key

A wallet is six systems that must agree. We build them as one product, with one team accountable for the whole path.

  • 01

    Key generation

    Keys are born inside the boundary and never leave it. Ceremony steps are written down and witnessed.

    • MPC or HSM-backed
    • Documented ceremony
    • Sealed backup material
  • 02

    Signing service

    One service signs. It checks policy first, then the request, then the limits. Nothing else touches a key.

    • Policy engine
    • Per-asset limits
    • Idempotent requests
  • 03

    Deposit handling

    Address issue, confirmation tracking and sweeps run as one path. Late chain reorgs are handled, not ignored.

    • Address derivation
    • Reorg-safe crediting
    • Scheduled sweeps
  • 04

    Withdrawal flow

    Every payout crosses a queue with checks and a human gate above a set size. Speed comes from tuning, not shortcuts.

    • Allow lists
    • Velocity caps
    • Break-glass hold
  • 05

    Chain coverage

    New chains land as plug-ins on one wallet core. Adding an asset does not fork the whole system.

    • UTXO and account models
    • Fee strategy per chain
    • Node or provider mix
  • 06

    Proof of balance

    Chain state is reconciled against the ledger every day. Gaps raise an alert before a customer finds them.

    • Daily reconciliation
    • Reserve reporting
    • Drift alerts

Controls

The path a payout takes

Nothing signs on the first ask. A withdrawal crosses four gates before a key is touched. Each gate writes its own record.

Payout path: request, then policy, then screening, then signing, then broadcast.

  • Who can move funds?

    Roles are narrow and separate. The person who requests a payout can never approve it.

  • What stops a bad payout?

    Allow lists, per-asset caps and screening run before signing. A failed check holds the request.

  • How is a transfer traced?

    Travel Rule data rides with the transfer. Both legs are stored with the signing record.

  • What does an auditor see?

    A signed, time-ordered log. Each entry links the request, the checks and the on-chain result.

Resilience

Backup and recovery, rehearsed

A backup you have never restored is a guess. We prove the recovery path before you hold a single customer coin.

  1. 01

    Threat model

    Week 1

    We list what can go wrong: insider, endpoint, vendor, chain. Each risk gets an owner and a control.

  2. 02

    Backup design

    Week 2

    Shares are split across sites and roles. No single person or room can rebuild a key alone.

  3. 03

    Recovery drill

    Before launch

    We restore keys in a test run with your staff. The runbook is proven, not assumed.

  4. 04

    Live operation

    Ongoing

    Rotation, drills and reviews run on a schedule. 24/7 cover with named engineers.

Engagement

Four ways to buy the work

Custody work often starts small and grows. The commercial model should follow it.

  • Fixed-scope build

    A defined wallet system at a fixed price. Best when the asset list is settled.

  • Dedicated team

    A standing squad with a lead. Best for long roadmaps and new chains each quarter.

  • Staff augmentation

    Senior engineers inside your team. Best when you own the plan and need key depth.

  • CTO advisory

    A custody model review before you commit. Best at the design stage.

Questions

Before you brief us

The four things buyers ask first. Ask the rest on the call.

Do you build custody in-house or use a provider?

Both. We build self-custody on MPC or HSM, or we wire your team into a licensed custodian. The trade-offs are costed in discovery.

Can you take over an existing wallet system?

Yes. We start with a key-handling and code review. Then we agree what to keep, what to wrap and what to rebuild.

How do you handle MiCA custody duties?

We build to the segregation, record-keeping and reporting duties your advisers scope. We are engineers, not a law firm.

Who owns the result?

You do. The system is bespoke and client-owned. There is no white-label lock-in and no per-seat licence later.

Tell us what you need to hold

Bring your asset list and your risk limits. We come back with a custody model, a control map and a costed plan. No demo theatre.