How to Evaluate a Digital Asset Custody Provider: The Questions That Actually Matter
Choosing custody infrastructure is one of the highest-stakes decisions an institution makes in digital assets: it is hard to reverse, and every other part of the operation builds on top of it. Yet most evaluations run on feature lists and brand names. This is the framework we teach institutional teams to apply to any provider, ours included: the questions to ask, the answers to expect, and the signals to watch for.
What is the single most important question to ask?
Can the provider prove, cryptographically, that no single party, including the provider itself, can move funds alone? Every provider will say its custody is secure. The question that separates them is whether that claim rests on proof or on trust: where the full private key exists, if anywhere; who could act alone in the worst case; and what evidence of both is available for audit. If the answer amounts to "trust our processes", the architecture rests on the very thing digital assets were designed not to require.
How should you evaluate the security architecture?
Ask for the threat model, and check that it maps to controls. A serious provider can name the adversary classes it defends against, from external attackers and organised cybercrime to privileged insiders, supply-chain compromise, physical coercion, and legal seizure, and show, for each, the specific control that addresses it and the evidence behind that control. Ask whether key material is protected by dedicated hardware, what happens if a share or device is lost, and whether the cryptography has been independently reviewed, with findings remediated rather than just assessed.
How should you evaluate governance and policy controls?
Check whether policy is enforced before signing or reviewed after. Approval quorums, spending limits, address whitelists, and sanctions screening should be conditions a transaction must meet to be signed at all, not a dashboard someone checks afterwards. Ask who can change the policies themselves, and whether that change also requires multiple approvers. Then ask for the audit trail: every action, from wallet creation to transfer approval, logged with who did it, who approved it, and when, in a record that cannot be altered.
What should you ask about dependence and exit?
Assume the relationship ends, and ask what happens then. If the provider froze your account, changed its terms, or exited the market tomorrow, what is your independent route back to your assets? Can you migrate to another provider, or to your own infrastructure, without the provider's cooperation? Who owns the data, the keys, and the deployment? Providers confident in their answer will put it in writing; providers who depend on lock-in will change the subject.
What should you ask about commercial terms?
Ask for the shape of the price, not just the number. Fees tied to assets under custody or transaction volume grow in exactly the months when everything else is off plan too. Ask what happens at renewal, when your negotiating position is weakest, and whether the provider will commit to its terms in advance. A provider unwilling to state the shape of its pricing plainly is telling you something about the relationship ahead.
The checklist: twelve questions for any custody provider
- Where does the full private key exist, if anywhere, at any point in its lifecycle?
- Can any single party, including you as the provider, move funds alone? Prove it.
- Which adversary classes does your threat model cover, and which control addresses each?
- Is key material protected by dedicated secure hardware, and how do you prove it?
- Has your cryptography been independently reviewed, and were the findings remediated?
- Are policies enforced as preconditions of signing, or reviewed after the fact?
- Who can change policies, and does that change itself require a quorum?
- What does the audit trail cover, and can it be altered?
- How are compliance checks, KYC, sanctions, Travel Rule, applied to each transaction?
- If you froze our account or exited the market, how do we reach our assets without you?
- Can we migrate to our own infrastructure later without rebuilding from scratch?
- What is the shape of your pricing, and what happens to it at renewal?
If you'd like to put this framework to work on your own evaluation, contact us. We're happy to answer your questions and book a demo for you.
Frequently asked questions
What is the biggest red flag when choosing a custody provider?
An answer that reduces to "trust us": security claims without cryptographic proof, a threat model that can't be shown, or an exit scenario the provider is unwilling to discuss in writing.
Should the provider's technology or its regulation matter more?
Both, and they answer different questions: regulation covers conduct and accountability, while architecture determines what is physically possible with your assets. A licence does not compensate for an architecture where a single party can move funds.
How long should a custody evaluation take?
Weeks, not days. A serious evaluation covers architecture, governance, compliance, exit, and commercial terms, and involves security, compliance and finance, not just the team that will use the product.
Can we run this evaluation without in-house crypto expertise?
Yes, but build the understanding first. A structured education session, or an advisory engagement that produces an evaluation framework your team owns, costs far less than discovering the gaps after deployment. This framework is what The Vault Institute teaches in full: a one-day Education Day gives your team the working understanding to apply it, and a four-to-six-week Advisory engagement produces The Vault Blueprint, an infrastructure plan you own regardless of which provider you choose.