Crypto Custody Technology: Methodology

This page explains how Counterparty Catalogue builds the Crypto Custody Technology table and where every number on it comes from. A product is listed here when the client holds at least one key share; a provider that also runs a licensed custody service appears in Crypto Custodians as a separate product.

Every fact on a record starts as a claim: from the provider's own website, documentation or trust center, a certificate register, or a public comparison sheet. A claim becomes a published fact only when we can point to a public page that states it. We store the page address, the exact words on that page, and the date we read them. If we cannot find the words, the cell stays empty and says so. We never estimate or scale a missing value. Answers a provider gave us directly show as provider-stated, with the date they gave them, until a public page confirms them.

Audits and certifications count as verified only when a public page names the report or certificate: for SOC 2, the auditor and the period covered; for ISO 27001, the certificate on the certification body's register rather than a badge on the provider's site.

The line above the table counts how many providers publish a verified SOC 2 Type 2 report. It counts active products only, and it appears only once enough providers clear the bar to make the number meaningful. A company that has stopped operating is shown with the date it stopped and is left out of the table and the count.

Anyone can dispute a fact from its row. A person reviews every dispute. A correction or removal is recorded with its reason and source and applied on the next data load, so the trail stays public.

What we record

  • Key control model (set): Who holds the key shares. A product can offer more than one model.
  • Key type (set): How the private keys are stored and used to sign. A product can use more than one.
  • Signing policy (text): How many of the key holders must approve a transaction, for example 2 of 3.
  • Policy controls (set): The kinds of rules a client can set on transactions. A product can offer more than one.
  • Key recovery (text): Who can rebuild the keys if the provider or the client loses them, and the named recovery partner if any.
  • Self-custody (boolean): Whether a client can hold every key share themselves.
  • Deployment (enum): Whether the software runs on the provider's cloud, in the client's own environment, or either.
  • Networks (set): Which families of blockchain the product supports, computed from the full network list where we have one.
  • Supported networks (list): Every blockchain the provider lists as supported on its own site on the checked date. Networks only, never tokens.
  • DeFi access (boolean): Whether a client can use decentralised finance protocols from custody.
  • Exchange integrations (text): Exchanges the product connects to directly, as named by the provider.
  • Off-exchange settlement (boolean): Whether a client can trade on an exchange while the assets stay in custody.
  • API access (enum): Whether clients can connect their own systems through an API.
  • Staking offered (boolean): Whether the product lets clients stake assets from custody.
  • Insurance type (set): The kinds of insurance the provider says it carries. Types only; whether a limit applies to one client is in the policy, not here.
  • Restricted jurisdictions (text): Countries the provider says it will not serve.
  • Pricing basis (enum): What the provider charges on.
  • List price (text): The entry price as the provider publishes it, for example 24 bps per year or from $800 per year. Never a low, medium or high tier.
  • Pricing page (text): The provider's public pricing page.
  • Pricing tiers (text): Every public tier the provider lists, one per line: tier, price, what it includes. Enterprise tiers without a price are listed as custom.

How a fact becomes verified

A fact is marked verified only when it carries a source URL a reader can open and the date it was checked. A fact resolved through a dispute also records who resolved it. A fact we could not confirm shows as "not verified"; a fact nobody has published shows as "not disclosed". Neither is a guess. Answers a provider gave us directly show as provider-stated, with the date they gave them, until a public page confirms them.

How to dispute a fact

Every fact and license on a Crypto Custody Technology fact sheet has a Dispute link. Sign in, pick a reason (wrong value, outdated, wrong source, or other), and add what you know. A change lands only after review, with its reason and source recorded.

Last updated