How the Non-Custodial Institutional Model Works

Bitpanda Enterprise Custody supports a non-custodial operating model for institutions that require direct control over the environment responsible for final blockchain signing.

In this model, the Hardware Security Module (HSM) responsible for final signing is deployed within the institution's environment.

Bitpanda Custody provides the integration, transaction orchestration and configurable policy controls, while the institution-operated HSM provides the final cryptographic enforcement boundary.

This creates a separation between custody technology and transaction orchestration and institutional control of the underlying cryptographic signing infrastructure.

 

Architecture overview

Non-Custodial Institutional Architecture
Click image to enlarge

At a high level, the transaction flow is:

Institution → Secure Connectivity → Bitpanda Custody → Institution-Operated HSM → Blockchain Network

The principal distinction from the custodial model is who operates the cryptographic signing environment.

1. Institutional control

Transactions originate from the institution's controlled environment.

This can include:

  • core banking, treasury or other institutional systems;
  • authorised users and approvers; and
  • institution-managed network and firewall infrastructure.

The institution retains its own governance around who can initiate and approve custody operations, while also operating the HSM environment responsible for final blockchain signing.

2. Secure connectivity

For an online on-premises deployment, the institution connects to Bitpanda Custody through secured connectivity, such as a site-to-site VPN using an IPsec tunnel.

This provides a protected communication path between the institution's infrastructure and the Bitpanda Custody environment.

3. Bitpanda Custody

Bitpanda Custody provides the integration and orchestration layer used to coordinate the custody transaction lifecycle.

GraphQL API

The GraphQL API provides the integration interface through which authorised institutional systems can interact with Bitpanda Custody.

Custody Services / Orchestration

Custody services coordinate transaction processing and the system processes required to move a transaction through the custody workflow.

Policy and Transaction Controls

Before a transaction proceeds to the institution-operated HSM, it can be subject to configurable governance and transaction controls.

These can include:

Wallet Policy
Defines the applicable approval structure, including quorum and approval requirements.

Allow List
Restricts transactions to approved destinations where configured.

Threshold Rules
Apply value-based approval controls.

Time Delay
Introduces an additional review period before execution where configured.

These controls form part of the custody transaction workflow and operate before final cryptographic signing.

4. Institution-Operated HSM

The institution-operated HSM provides the final cryptographic enforcement boundary.

Before custody-key use and final signing, the HSM validates:

  1. the transaction request;
  2. the applicable wallet policy;
  3. the required cryptographic approvals; and
  4. the authorised policy state.

Only after the required validations have succeeded can the relevant blockchain key be derived and used for final signing. This separates access to the custody platform, transaction authorisation and final custody-key use.

In the non-custodial model, the institution operates the infrastructure in which these final cryptographic operations occur.

5. Online and Offline On-Premises Infrastructure

Two institution-operated HSM deployment approaches are available within the non-custodial model.

Online On-Premises

The institution operates its HSM environment online, supporting live transaction signing. This model is suited to institutions requiring real-time operational access while retaining direct control over the cryptographic signing environment.

Offline On-Premises

The institution operates an offline or air-gapped HSM environment. This provides increased infrastructure isolation and supports operating models where offline signing and additional operational controls are required.

6. Blockchain Networks

Following successful HSM validation and final signing, the signed transaction can proceed to the appropriate supported blockchain network.

The blockchain network then processes the signed transaction according to the rules of that network.

What control does the institution retain?

The non-custodial model provides the institution with direct operational control over the infrastructure responsible for custody-key operations and final blockchain signing.

The operating model can combine:

  • institutional user and access controls;
  • institution-controlled network infrastructure;
  • transaction initiation controls;
  • approval quorums;
  • wallet policies;
  • approved-destination controls;
  • value-based approval controls;
  • time delays;
  • institution-operated HSM infrastructure; and
  • HSM-enforced cryptographic controls.

The result is a layered control model in which Bitpanda provides the custody technology, orchestration and configurable transaction controls, while the institution operates the final cryptographic signing environment.

 

Further information

For more information about transaction controls, HSMs and cryptographic signing, see:

 

Was this article helpful?
0 out of 0 found this helpful