OUR EXPERTISE

Custody architecture and key governance

Define who controls assets and how that control is exercised

01 / XCUSTY

XCusty develops custody architecture around the client's asset model, operating responsibilities and risk tolerance. The starting point is a precise allocation of control: which party holds key material, which party authorizes transactions and which party is responsible for maintaining access during an incident.

Wallet and account structures

We can design segregated wallets, account hierarchies and treasury structures suited to the operating model. The architecture identifies the relationship between addresses, customer records, internal balances and external custody accounts. This makes it easier to trace an asset movement to the correct business or client account.

Signing arrangements

Depending on requirements and supported providers, a solution may use multisignature controls, multiparty computation or hardware-backed signing. These are distinct approaches with different operational dependencies. The selected arrangement is evaluated for access control, approval thresholds, resilience and recovery requirements.

The design also addresses key generation, secure enrollment, signer changes, backup procedures and the handling of compromised credentials. Sensitive signing operations should be separated from general application access and routine developer permissions.

Separation of responsibilities

The person who creates a payment request may be different from the person who approves it. Administrators who configure the system may also need restrictions on their ability to move assets. We help translate these requirements into roles, permissions and approval policies that fit the organization.

Recovery and continuity

A recovery plan defines what happens when a signer is unavailable, credentials are compromised or a provider cannot be reached. It identifies the authorized recovery participants, evidence requirements and conditions for restoring normal operation. Recovery procedures are tested within the agreed scope before reliance is placed on them.

Custody engagement outputs

The expected output is an architecture pack covering asset ownership, wallet topology, signing responsibilities, approval policies, provider dependencies and recovery procedures. The contracting documents separately identify the custody provider and any organization that has authority to move client assets.

YOUR NEXT CHAPTER

Complex ambitions. Let’s build them together.

Bring us the challenge. We’ll bring the people, architecture and a clear path forward.

Start a conversation