Understanding Custodial and Non-Custodial Deployment Models

Bitpanda Enterprise Custody supports different deployment models to accommodate the security, regulatory and operational-control requirements of institutional clients.

A fundamental consideration is whether the institution uses a custodial or non-custodial operating model.

The principal distinction is who operates the cryptographic environment responsible for final blockchain signing.

Custodial and Non-Custodial Deployment Models
Click image to enlarge

Custodial model

In a custodial model, the cryptographic infrastructure used to protect custody keys and perform blockchain signing is operated by Bitpanda Custody.

Institutions can retain governance over areas such as users, transaction initiation, approval structures and wallet policies while Bitpanda operates the underlying custody infrastructure.

Two hosting approaches are available.

Multi-Tenant Hosting

Multiple clients use a secure shared HSM cluster, with logical separation of keys and policies between tenants.

This model is designed to provide managed custody infrastructure without requiring the institution to operate dedicated HSM hardware.

Dedicated Hosting

A dedicated HSM cluster is allocated to the institution and operated by Bitpanda Custody.

This provides additional physical and logical infrastructure isolation while retaining a managed operating model.

Non-custodial model

In a non-custodial model, the institution operates the HSM environment responsible for final blockchain signing.

Bitpanda Custody provides the custody technology, transaction orchestration and policy workflow, while the institution retains control of the environment containing the final cryptographic signing boundary.

Two principal deployment approaches are supported.

Online On-Premises

The institution operates an online HSM environment that supports live transaction signing and policy enforcement.

This model is designed for institutions requiring real-time operational access while retaining direct control of the signing environment.

Offline On-Premises

The institution operates an offline, air-gapped HSM environment.

This provides greater infrastructure isolation and is suited to operating models requiring offline signing and additional manual controls.

Choosing an operating model

The appropriate model depends on the institution's requirements.

Typical considerations include:

  • regulatory responsibility;
  • required level of operational control;
  • infrastructure and security requirements;
  • transaction volumes and complexity;
  • automation requirements;
  • online versus offline signing requirements; and
  • business continuity and recovery requirements.

The selected deployment model does not remove the need for transaction governance. Wallet policies, approval requirements, roles and transaction controls remain part of the overall custody security model.

 

Further information

For more information about the different custody operating models and the security controls that support them, see:

Was this article helpful?
0 out of 0 found this helpful