Bitpanda Enterprise Custody supports different deployment models to accommodate the security, regulatory and operational-control requirements of institutional clients.
A fundamental consideration is whether the institution uses a custodial or non-custodial operating model.
The principal distinction is who operates the cryptographic environment responsible for final blockchain signing.
Custodial model
In a custodial model, the cryptographic infrastructure used to protect custody keys and perform blockchain signing is operated by Bitpanda Custody.
Institutions can retain governance over areas such as users, transaction initiation, approval structures and wallet policies while Bitpanda operates the underlying custody infrastructure.
Two hosting approaches are available.
Multi-Tenant Hosting
Multiple clients use a secure shared HSM cluster, with logical separation of keys and policies between tenants.
This model is designed to provide managed custody infrastructure without requiring the institution to operate dedicated HSM hardware.
Dedicated Hosting
A dedicated HSM cluster is allocated to the institution and operated by Bitpanda Custody.
This provides additional physical and logical infrastructure isolation while retaining a managed operating model.
Non-custodial model
In a non-custodial model, the institution operates the HSM environment responsible for final blockchain signing.
Bitpanda Custody provides the custody technology, transaction orchestration and policy workflow, while the institution retains control of the environment containing the final cryptographic signing boundary.
Two principal deployment approaches are supported.
Online On-Premises
The institution operates an online HSM environment that supports live transaction signing and policy enforcement.
This model is designed for institutions requiring real-time operational access while retaining direct control of the signing environment.
Offline On-Premises
The institution operates an offline, air-gapped HSM environment.
This provides greater infrastructure isolation and is suited to operating models requiring offline signing and additional manual controls.
Choosing an operating model
The appropriate model depends on the institution's requirements.
Typical considerations include:
- regulatory responsibility;
- required level of operational control;
- infrastructure and security requirements;
- transaction volumes and complexity;
- automation requirements;
- online versus offline signing requirements; and
- business continuity and recovery requirements.
The selected deployment model does not remove the need for transaction governance. Wallet policies, approval requirements, roles and transaction controls remain part of the overall custody security model.
Further information
For more information about the different custody operating models and the security controls that support them, see: