Skip to content
counterpartycatalogue.
CUSTODY / CATEGORY GUIDE

Crypto Custody Technology

Looking for Crypto Custodians? See Crypto Custodians.

12 of 23 providers publish a verified SOC 2 Type 2 report

Crypto custody technology: software that lets clients manage and secure their own digital assets, with shared or full client control of the key material. A product is listed here when the client holds at least one key share; a provider that also runs a licensed custody service appears in Crypto Custodians as a separate product.

23 digital asset providers compete in this crypto custody technology market.

THE PROVIDER LANDSCAPE

Compare the facts.

Alphabetical · No ranking
23 products to explore
Product Company Key control model Key type Policy controls Self-custody Networks API access SOC 2 Type 2 report ISO 27001 certified Also in
AnchorWatch Shared keys Multi-sig Approval quorums, Amount and time limits, Address allow-list * not disclosed Bitcoin Yes not disclosed not disclosed
BitGo not disclosed HSM, MPC, Multi-sig Address allow-list not disclosed Bitcoin, Ethereum, Other layer 1s, Layer 2s * Yes Yes not disclosed Off-Exchange Settlement Tokenization Platforms
Cobo Shared keys HSM, MPC, Multi-sig * Approval quorums, Address allow-list, Smart contract allow-list not disclosed not disclosed Yes Yes Yes Crypto Custodians Off-Exchange Settlement
Copper Shared keys * MPC Approval quorums, Address allow-list, Amount and time limits * not disclosed Bitcoin, Ethereum, Solana, Other layer 1s Yes Yes not disclosed Crypto Custodians Crypto Lenders
Cordial Systems Client-controlled, Shared keys * MPC Approval quorums not disclosed Bitcoin, Ethereum, Solana, Other layer 1s, Layer 2s * Yes Yes not disclosed
Dfns Client-controlled, Shared keys, Provider-controlled * HSM, MPC Approval quorums not disclosed Bitcoin, Ethereum, Solana, Other layer 1s * Yes Yes Yes
Finoa not disclosed not disclosed not disclosed not disclosed not disclosed not disclosed not disclosed not disclosed
Fireblocks Shared keys * MPC Approval quorums not disclosed not disclosed Yes Yes not disclosed Off-Exchange Settlement Tokenization Platforms
Fordefi Shared keys * MPC Address allow-list, Smart contract allow-list not disclosed Bitcoin, Ethereum, Solana, Other layer 1s, Layer 2s Yes Yes not disclosed
Galaxy Client-controlled * HSM, MPC Approval quorums, Address allow-list * not disclosed Other layer 1s, Layer 2s not disclosed Yes * not disclosed
Ledger Client-controlled HSM, Multi-sig not disclosed not disclosed Bitcoin, Ethereum, Solana, Other layer 1s, Layer 2s Yes Yes not disclosed
Liminal Shared keys * HSM, MPC, Multi-sig * Approval quorums not disclosed Bitcoin, Ethereum, Solana, Other layer 1s, Layer 2s Yes Yes not disclosed
MPCVault Shared keys * MPC, Multi-sig Address allow-list, Smart contract allow-list not disclosed Bitcoin, Ethereum, Solana, Other layer 1s Yes Yes * not disclosed
Narval not disclosed not disclosed not disclosed not disclosed not disclosed not disclosed not disclosed not disclosed
Onramp not disclosed Multi-sig not disclosed not disclosed Bitcoin * Yes not disclosed not disclosed
Rigsec not disclosed HSM not disclosed not disclosed not disclosed not disclosed not disclosed not disclosed
Ripple Client-controlled HSM, MPC not disclosed not disclosed Bitcoin, Ethereum, Solana, Other layer 1s, Layer 2s Yes * Yes not disclosed
Safeheron Client-controlled not disclosed not disclosed not disclosed Ethereum, Solana, Other layer 1s, Layer 2s Yes Yes not disclosed
Zodia Custody Shared keys * HSM, MPC Approval quorums, Amount and time limits, Address allow-list * not disclosed Bitcoin, Ethereum, Solana, Other layer 1s, Layer 2s * Yes not disclosed Yes
Taurus not disclosed HSM, MPC Address allow-list not disclosed not disclosed Yes not disclosed not disclosed
Tholos Client-controlled * MPC Approval quorums, Smart contract allow-list, Address allow-list * not disclosed Bitcoin, Ethereum, Solana, Other layer 1s, Layer 2s Yes not disclosed not disclosed
Unchained not disclosed Multi-sig not disclosed not disclosed Bitcoin not disclosed not disclosed not disclosed
Utila Shared keys * MPC Approval quorums not disclosed Bitcoin, Ethereum, Solana, Other layer 1s, Layer 2s * Yes Yes not disclosed Crypto Payments

Compact view · Select “Show full text” to expand longer values. Scroll across the table to see every field. Select a product for its sources and full profile.

* provider-stated, not yet verified

Reading this table

Key control model

Who holds the key shares. A product can offer more than one model.

Provider-controlled
The provider holds every key or key share. The client cannot move funds without the provider.
Shared keys
The provider and the client each hold key shares, and both must approve. Some providers put a third party in the provider's seat.
Client-controlled
The client holds every key or key share. The provider can never move funds.

Key type

How the private keys are stored and used to sign. A product can use more than one.

HSM
Hardware security module: a locked device that generates, stores and signs with the key, so the key never leaves it.
MPC
Multi-party computation: the key is split into shares on different machines that sign together without ever joining the key.
Multi-sig
The blockchain itself requires several separate keys to approve one transaction.
Shamir secret sharing
One key split into parts, any few of which rebuild it. A backup scheme, not a signing scheme.

Signing policy

How many of the key holders must approve a transaction, for example 2 of 3.

Policy controls

The kinds of rules a client can set on transactions. A product can offer more than one.

Address allow-list
Approved addresses or tokens only, with no approval quorums. Called basic in the DigOpp comparison chart.
Approval quorums
Flexible admin quorums plus allow-lists. Called core in the DigOpp chart.
Amount and time limits
Limits by amount or time window; above them, extra approval or a delay applies. Called threshold-based in the DigOpp chart.
Smart contract allow-list
Approved smart contracts and functions a wallet may call. Called contract-level in the DigOpp chart.

Key recovery

Who can rebuild the keys if the provider or the client loses them, and the named recovery partner if any.

Self-custody

Whether a client can hold every key share themselves.

Deployment

Whether the software runs on the provider's cloud, in the client's own environment, or either.

Hosted
Runs on the provider's cloud.
Self-hosted
Runs in the client's own environment.
Either
The client chooses hosted or self-hosted.

Networks

Which families of blockchain the product supports, computed from the full network list where we have one.

Bitcoin
The Bitcoin network.
Ethereum
Ethereum mainnet.
Solana
The Solana network.
Other layer 1s
Other base-layer blockchains such as Avalanche, Polkadot, Cardano or XRP Ledger.
Layer 2s
Networks that settle onto Ethereum, such as Arbitrum, Optimism and Base.

Supported networks

Every blockchain the provider lists as supported on its own site on the checked date. Networks only, never tokens.

DeFi access

Whether a client can use decentralised finance protocols from custody.

Exchange integrations

Exchanges the product connects to directly, as named by the provider.

Off-exchange settlement

Whether a client can trade on an exchange while the assets stay in custody.

API access

Whether clients can connect their own systems through an API.

Yes
Clients can connect through an API.
On request
Clients can ask for API access; it is not offered by default.
No
No client API.

Staking offered

Whether the product lets clients stake assets from custody.

Insurance type

The kinds of insurance the provider says it carries. Types only; whether a limit applies to one client is in the policy, not here.

Crime
Covers theft by employees or outsiders, including hacks of the provider's systems.
Specie
Covers loss or damage of keys held in cold storage, the way vault contents are insured.
Cyber
Covers losses from cyber attacks and data breaches.
Errors and omissions
Covers losses from the provider's mistakes in providing its service.
Directors and officers
Covers claims against the company's directors and officers. Not a client protection.

Restricted jurisdictions

Countries the provider says it will not serve.

Pricing basis

What the provider charges on.

Assets under custody
A yearly percentage of the value held.
Transaction volume
A fee on what moves in or out.
Assets and volume
Both a percentage of value held and a fee on movement.
Flat fee
A fixed monthly or yearly price.
Custom
No published rate; priced per client.

List price

The entry price as the provider publishes it, for example 24 bps per year or from $800 per year. Never a low, medium or high tier.

Pricing page

The provider's public pricing page.

Pricing tiers

Every public tier the provider lists, one per line: tier, price, what it includes. Enterprise tiers without a price are listed as custom.

Headcount

Number of employees the company states.

Funding raised (USD)

Total outside funding the company states it has raised, in US dollars.

Regulator of record

The regulator the company names as its main supervisor.

SOC 2 Type 2 report

An independent auditor tested the company's security controls over a period of months. The audit firm and the period are in the note.

SOC 2 Type 1 report

An independent auditor checked the company's security controls at one point in time. Weaker than Type 2.

SOC 1 Type 2 report

An independent auditor tested the controls behind the company's financial reporting over a period of months.

SOC 1 Type 1 report

An independent auditor checked the controls behind the company's financial reporting at one point in time.

ISO 27001 certified

The company holds an ISO/IEC 27001 information security certificate. Certificate number, certification body and expiry are in the note; verified means we found it on a public certificate register.

Annual penetration test

An outside firm tries to break into the company's systems at least once a year. The firm is in the note when named.

CCSS level

CryptoCurrency Security Standard level the company was audited to. Level 3 is the highest.

Level 1
Basic CCSS controls audited.
Level 2
Stronger CCSS controls audited, including key redundancy.
Level 3
The highest CCSS level: full controls, tested, with formal policies.

Cryptographic audit

An independent review of the signing scheme itself, not the company's processes. Firm and year in the note.

About this category

Crypto custody technology: software that lets clients manage and secure their own digital assets, with shared or full client control of the key material. A product is listed here when the client holds at least one key share; a provider that also runs a licensed custody service appears in Crypto Custodians as a separate product.