Full-stack custody,built for institutionaloperations

The Vault Custody combines secure digital asset infrastructure with the operational tools institutions actually need, built to integrate with the systems you already run, with your assets under your control at every level.

Key sovereignty, configured to your model

As a regulated digital asset platform, The Vault is built on threshold MPC and HSM-anchored key protection. The level of key sovereignty is something you choose: from a fully managed SaaS deployment, through hybrid models with a self-hosted signer, to full on-premise where every key and every operation stays inside your perimeter. The cryptography is the same at every level; the control surface scales with how much of the stack you want to run yourself.

Omnichannel Access

The custody platform runs as a web portal, mobile application, and API, giving your operations, compliance, and treasury teams structured, permissioned access to every wallet and transaction across your infrastructure.

The Vault Custody app, live on

Built for Governance

Multi-wallet management, real-time transaction monitoring, and a robust policy engine that governs every fund movement before it reaches the blockchain.

02 Deployment options

Three deployment
options,
configured
to your model

Choose the infrastructure model that fits your operational requirements.

How deployment works

SaaS

Hosted custody platform
  • Fully hosted custody platform
  • No infrastructure setup required
  • Full or shared wallet control
  • 24/7 access and maintenance

Hybrid

Split across both perimeters
  • Some components in your perimeter, some in ours
  • Designed around what has to stay where
  • The same security model as every configuration
  • Your infrastructure team involved part-time

On-premise

Full on-premise solution
  • Full on-premise deployment
  • Zero external dependencies
  • All data/keys within your perimeter
  • Hot, warm, or cold key distribution
03 Custody controls

Custody controls
built for scale

The full control layer for every account, key, and transaction across your custody platform.

Multiple Wallets

Unlimited wallets and addresses from a single interface.

Role-based Teamwork

Multi-user access with clearly defined roles and permission levels.

Process Automation

API-driven execution of operational workflows.

Advanced Key Handling

Secure private key generation, storage, and usage with modern cryptography.

System Administration

Centralised user and policy configuration.

Operational Monitoring

Detailed reporting on balances, transactions and approvals.

Transaction Governance

Rule-based approval policies, spending limits, and address whitelists.

Compliance Tools

Counterparty screening for AML support.

04 Product video

See every transaction.Control every key

Meet your platform for secure safeguarding and processing of digital assets.

05 Secure transaction flow

Six governed stages. Only valid, authorised operations reach the blockchain

Every step is recorded in a tamper-resistant audit trail. Full attribution on every event.

Policy Setup

Define execution rules, approval routes, spending limits, and whitelisted addresses.

Transaction Initiation

Create a transaction via web portal, mobile app, or API.

Policy Validation

Automatic cross-check against all predefined governance rules.

Approval

Transactions are approved, rejected, or escalated for multi-user confirmation.

Signing

Executed via MPC key shares across devices and TEE servers. No complete key is ever assembled.

Execution

Submitted to the blockchain with a tamper-resistant audit trail (initiator, approvers, timestamps).

06 Security & compliance

Security architecture & compliance controls

Security and compliance standards
  • Member of VQF active
  • SOC 2 active
  • ISO 27001 in progress
  • Security Audit complete

MPC and HSM Key Security

The Vault is built on true threshold MPC, a T-of-N signature scheme where no complete private key is ever assembled in a single location, with HSM-anchored protection available where hardware-backed key storage is required. Key shares are distributed across client devices and TEE-secured servers, and the client retains sole control over their keys at all times.

This architecture eliminates the risk of key theft even in the event of a server breach, a standard that most institutional digital asset custody solutions do not meet.

See security
Compliance & Governance

Talk to an expert

Ready to take control of your digital asset operations?