Key custody
Wallet and custody engineering,
keys you can prove.
We design and build wallet systems for crypto startups, licensed VASPs and banks. One EU team owns key generation, signing policy, sweeps and the audit trail. The result is custody your ops team can run and your auditor can read.
- EU-based engineers
- MiCA-ready architecture
- AML and Travel Rule aware
Key tiers
Three tiers, one policy
Splitting funds by tier is the oldest custody control there is. It still works. Each tier holds a different amount and answers to a different rule.
Trading balances sit next door in our exchange build practice.
-
Hot tier
- Holds
- Working float
- Signing
- Automated, policy-bound
- Approval
- Rules only
Customer withdrawals and venue settlement.
-
Warm tier
- Holds
- Daily top-up
- Signing
- MPC quorum
- Approval
- Two named people
Refills the hot tier on a set schedule.
-
Cold tier
- Holds
- Reserve
- Signing
- HSM, offline
- Approval
- Quorum plus dual control
Long-term storage. Moved rarely, never in a hurry.
Scope
What we build around the key
A wallet is six systems that must agree. We build them as one product, with one team accountable for the whole path.
-
01
Key generation
Keys are born inside the boundary and never leave it. Ceremony steps are written down and witnessed.
- MPC or HSM-backed
- Documented ceremony
- Sealed backup material
-
02
Signing service
One service signs. It checks policy first, then the request, then the limits. Nothing else touches a key.
- Policy engine
- Per-asset limits
- Idempotent requests
-
03
Deposit handling
Address issue, confirmation tracking and sweeps run as one path. Late chain reorgs are handled, not ignored.
- Address derivation
- Reorg-safe crediting
- Scheduled sweeps
-
04
Withdrawal flow
Every payout crosses a queue with checks and a human gate above a set size. Speed comes from tuning, not shortcuts.
- Allow lists
- Velocity caps
- Break-glass hold
-
05
Chain coverage
New chains land as plug-ins on one wallet core. Adding an asset does not fork the whole system.
- UTXO and account models
- Fee strategy per chain
- Node or provider mix
-
06
Proof of balance
Chain state is reconciled against the ledger every day. Gaps raise an alert before a customer finds them.
- Daily reconciliation
- Reserve reporting
- Drift alerts
Controls
The path a payout takes
Nothing signs on the first ask. A withdrawal crosses four gates before a key is touched. Each gate writes its own record.
Payout path: request, then policy, then screening, then signing, then broadcast.
-
Who can move funds?
Roles are narrow and separate. The person who requests a payout can never approve it.
-
What stops a bad payout?
Allow lists, per-asset caps and screening run before signing. A failed check holds the request.
-
How is a transfer traced?
Travel Rule data rides with the transfer. Both legs are stored with the signing record.
-
What does an auditor see?
A signed, time-ordered log. Each entry links the request, the checks and the on-chain result.
Resilience
Backup and recovery, rehearsed
A backup you have never restored is a guess. We prove the recovery path before you hold a single customer coin.
- 01
Threat model
Week 1
We list what can go wrong: insider, endpoint, vendor, chain. Each risk gets an owner and a control.
- 02
Backup design
Week 2
Shares are split across sites and roles. No single person or room can rebuild a key alone.
- 03
Recovery drill
Before launch
We restore keys in a test run with your staff. The runbook is proven, not assumed.
- 04
Live operation
Ongoing
Rotation, drills and reviews run on a schedule. 24/7 cover with named engineers.
Engagement
Four ways to buy the work
Custody work often starts small and grows. The commercial model should follow it.
-
Fixed-scope build
A defined wallet system at a fixed price. Best when the asset list is settled.
-
Dedicated team
A standing squad with a lead. Best for long roadmaps and new chains each quarter.
-
Staff augmentation
Senior engineers inside your team. Best when you own the plan and need key depth.
-
CTO advisory
A custody model review before you commit. Best at the design stage.
Questions
Before you brief us
The four things buyers ask first. Ask the rest on the call.
Do you build custody in-house or use a provider?
Both. We build self-custody on MPC or HSM, or we wire your team into a licensed custodian. The trade-offs are costed in discovery.
Can you take over an existing wallet system?
Yes. We start with a key-handling and code review. Then we agree what to keep, what to wrap and what to rebuild.
How do you handle MiCA custody duties?
We build to the segregation, record-keeping and reporting duties your advisers scope. We are engineers, not a law firm.
Who owns the result?
You do. The system is bespoke and client-owned. There is no white-label lock-in and no per-seat licence later.
Tell us what you need to hold
Bring your asset list and your risk limits. We come back with a custody model, a control map and a costed plan. No demo theatre.