
ALTERNATIVE SYSTEMS · DIGITAL ASSETS
Custody & Wallet
Infrastructure Framework
Custody is the one function in digital assets where an operational mistake is irreversible, which is why the controls are audited before the technology is admired. We build the institution to that standard — licensing and capital position, key generation and signing policy, segregation and wallet architecture, withdrawal authorisation and recovery procedures, and independent attestation.
THE SPECIFICATION
Architecture & Audience
A digital asset custodian holds keys. Everything else — the licence, the insurance, the audit, the client interface — exists to make that holding trustworthy. There is no partial failure available: a key compromised is an asset gone, irreversibly and publicly, and no institution has recovered its standing after one.
Institutions building qualified custody as a regulated service; exchanges and brokers separating custody from execution; and groups requiring proprietary custody they control rather than outsource.
What We Deliver
A complete architecture, designed, launched, and managed
We define the custody model — qualified custodian, sub-custodian, or self-custody tooling — and manage the licence or registration process in the target jurisdiction. Model selection determines the regulatory framework, capital requirement, and insurance obligations that apply.
We design and conduct the key generation ceremony: the procedures, witness arrangements, hardware security, and documentation that produce keys in a way that can be audited and that eliminates single points of failure from the first moment of existence.
We design the signing architecture — multi-party computation, hardware security modules, or multi-signature — that distributes key control across the required number of parties without creating a recovery gap that defeats the security model. Architecture is selected for the client base and asset scope.
We implement the account and wallet structure that segregates client assets from the custodian’s own holdings and from each other at the level the licence and the client mandate require. Segregation is enforced at the wallet level, not only at the ledger level.
We design the access control framework and signing quorum policy that governs who can authorise a withdrawal, under what conditions, and with what secondary approvals. Policy is documented, tested, and enforced by the signing architecture rather than by procedure alone.
We manage the insurance placement process for the custody institution: crime, specie, and technology coverage appropriate to the assets under custody, the signing architecture, and the jurisdictions in which assets are held. Coverage gaps are identified before assets are onboarded.
We design and test the disaster recovery and key inheritance procedures that allow the institution to restore access to client assets if the primary signatories are unavailable. Recovery procedures are tested before go-live and reviewed whenever the signing architecture changes.
We establish the independent attestation and audit arrangement — proof of reserves, SOC 2, or bespoke examination — that gives clients and regulators verifiable evidence that assets are held as stated. Attestation is conducted on a schedule the regulator and institutional clients accept.
We build the reporting infrastructure that delivers the capital, reserve, and regulatory returns required by the custody institution’s jurisdiction and the client reporting required by its mandates. All reporting is reconciled against the on-chain position before delivery.
What We Deliver
A complete architecture, designed, launched, and managed
We define the custody model — qualified custodian, sub-custodian, or self-custody tooling — and manage the licence or registration process in the target jurisdiction. Model selection determines the regulatory framework, capital requirement, and insurance obligations that apply.
We design and conduct the key generation ceremony: the procedures, witness arrangements, hardware security, and documentation that produce keys in a way that can be audited and that eliminates single points of failure from the first moment of existence.
We design the signing architecture — multi-party computation, hardware security modules, or multi-signature — that distributes key control across the required number of parties without creating a recovery gap that defeats the security model. Architecture is selected for the client base and asset scope.
We implement the account and wallet structure that segregates client assets from the custodian’s own holdings and from each other at the level the licence and the client mandate require. Segregation is enforced at the wallet level, not only at the ledger level.
We design the access control framework and signing quorum policy that governs who can authorise a withdrawal, under what conditions, and with what secondary approvals. Policy is documented, tested, and enforced by the signing architecture rather than by procedure alone.
We manage the insurance placement process for the custody institution: crime, specie, and technology coverage appropriate to the assets under custody, the signing architecture, and the jurisdictions in which assets are held. Coverage gaps are identified before assets are onboarded.
We design and test the disaster recovery and key inheritance procedures that allow the institution to restore access to client assets if the primary signatories are unavailable. Recovery procedures are tested before go-live and reviewed whenever the signing architecture changes.
We establish the independent attestation and audit arrangement — proof of reserves, SOC 2, or bespoke examination — that gives clients and regulators verifiable evidence that assets are held as stated. Attestation is conducted on a schedule the regulator and institutional clients accept.
We build the reporting infrastructure that delivers the capital, reserve, and regulatory returns required by the custody institution’s jurisdiction and the client reporting required by its mandates. All reporting is reconciled against the on-chain position before delivery.
Infrastructure Selection
X-CHASE holds no commercial interest in any provider, assessing them strictly on live performance, structural fit, and renewal terms. Providers are named exclusively under formal engagement, never on a public website.