Skip to content

Insights

Digital asset custody, explained

Digital asset custody is the safekeeping of cryptocurrencies and tokens on behalf of a business by a specialist provider, using secure key management, access controls and segregation. Businesses use a regulated custodian to reduce operational risk and meet compliance expectations.

For a business holding digital assets — whether that's treasury reserves or funds you hold for clients — custody comes down to one uncomfortable question: who controls the private keys, and under what rules? A crypto wallet is only ever as safe as the key behind it, and a private key is a single string that, once copied or lost, cannot be reissued. Digital asset custody is the safekeeping of crypto and tokens by a specialist provider that handles key generation, storage, signing and segregation on your behalf, so the operational and security burden of holding those keys doesn't sit inside your own business.

I run a regulated payments and settlement operation, and custody is the part of the stack that clients scrutinise hardest before they commit balances. What follows is how it actually works, and how to judge a provider.

What a custodian actually does

Strip away the branding and a custodian is doing three jobs.

Key management. This is the core of it. Keys have to be generated in a controlled environment, stored so that no single person or single machine can move funds unilaterally, and used only under a defined signing policy. In practice that means separating access by temperature: keys for assets that need to move quickly are held in a warmer, more available tier, while the bulk sits in cold storage that is deliberately harder to reach. Serious providers spread the ability to authorise a transaction across multiple parties or devices — whether through hardware security modules or multi-party computation, the principle is the same. No lone key on a laptop, no single point of compromise.

Segregation. Client assets are kept distinct from the provider's own balance sheet and, where required, from each other. This matters most in the scenario nobody likes to picture: if the provider fails, properly segregated client assets are identifiable and not part of the general creditor pool. Segregation is an accounting and legal discipline as much as a technical one — it only counts if the records and the entity structure hold up.

Controls and audit. Every movement happens under a signing policy — who can request, who must approve, what thresholds trigger extra sign-off — and every action is logged. A real audit trail lets you reconstruct exactly who did what, when, and under whose authorisation, months later and under scrutiny.

Custody vs self-custody: the real trade-offs

Self-custody is not wrong. For small, occasional amounts it's often the sensible choice, and it keeps you free of counterparty exposure to any provider. The trouble starts when the balances grow and the operation has to run every day.

At that point you inherit a full security function. Someone has to hold backup keys and test recovery. Someone has to enforce that no single employee can move funds alone. You need coverage for staff turnover, for a lost device, for the person who set everything up leaving the company. Lose a key and the assets are simply gone — there is no reset link. Concentrate signing authority in one trusted hand and you've built an internal-fraud risk instead. Most treasury and operations teams weren't hired to run a key-management programme to institutional standard, and the cost of doing it badly is total and irreversible. Using a custodian moves that specific risk to a party whose entire business is running it under controls, and who is examined on whether they do.

How custody supports compliance and audit

Custody is where a lot of your compliance story is actually told. When an auditor, a bank partner or a regulator asks how client assets are held and protected, "we keep the keys ourselves" rarely satisfies them. A regulated custodian gives you a cleaner answer: assets held under a named entity, segregated, with documented controls and a signing policy you can point to.

The audit trail does quiet, heavy work here. Proof-of-reserves and balance reconciliation depend on being able to show holdings at a point in time and account for every movement since. Anti-money-laundering and travel-rule obligations are easier to meet when transaction records are complete and consistent by design rather than reassembled after the fact. And when your own auditors test controls at year end, a custodian with defined signing policies and access logs turns what could be a painful review into a document request.

Custody for platforms (offering it to your own customers)

If you run a platform — an exchange, a marketplace, a fintech app, a wallet — custody stops being an internal question and becomes a product decision. Your users are trusting you to hold their assets safely, and you carry that liability whether or not you're equipped for it.

Broadly there are two routes. You can integrate a custodian's infrastructure behind your own interface, so your customers experience your brand while the key management, segregation and controls run on regulated rails underneath. Or you take on more of the stack yourself and accept the corresponding operational and regulatory weight. The white-label route lets a platform offer institutional-grade safekeeping without building a security programme from scratch, which for most platforms is the difference between shipping this quarter and not shipping at all.

What to check

Before you place assets with any provider, press on four things:

  • Regulatory standing. Which entity holds the assets, in which jurisdiction, under what authorisation? Vague answers here are the reddest flag there is.
  • Segregation. Are client assets genuinely separated from the provider's own, and how is that evidenced in the records and the legal structure?
  • Controls. Signing policies, access management, and — often overlooked — recovery. Ask what happens when a key or a device is lost.
  • Operational track record. How long have they run this, at what scale, and can they show clean audit and reconciliation history?

Direct or white-label

You can use custody directly for your own treasury or client funds, or, if you're a platform, offer it to your own customers under your own brand. We provide custody through regulated entities with segregation and institutional controls; the specifics — which entity, which jurisdiction, which assets — depend on where you and your clients sit. See digital asset custody and white-label custody.

This article is general information, not financial, legal or tax advice. Availability depends on jurisdiction and eligibility.

Frequently asked questions

What is digital asset custody?

The safekeeping of digital assets for a business by a specialist provider, using secure key management, segregation and controls — so the business doesn't carry the operational and security risk of holding private keys itself.

Why not just self-custody?

At business scale, key management, signing policy, segregation and recovery are hard to run safely. A regulated custodian assumes that risk under controls and audit, which clients increasingly expect.

Is custody regulated?

It can be. Xchange360 offers custody through regulated entities with segregation and institutional controls; specifics depend on jurisdiction.

Move your money where it needs to go