How the Custodial Institutional Model Works

Bitpanda Enterprise Custody supports a custodial operating model in which Bitpanda operates the cryptographic infrastructure responsible for custody-key protection and final blockchain signing.

The institution retains governance over its users, transaction initiation and configured approval processes, while Bitpanda Custody provides the transaction orchestration, configurable policy controls and HSM infrastructure required to execute authorised blockchain transactions.

This creates a separation between institutional transaction governance and operation of the underlying cryptographic infrastructure.

Architecture overview

Screenshot 2026-09-25 at 12.07.03.png

At a high level, the transaction flow is:

Institution → Secure Connectivity → Bitpanda Custody → Bitpanda-Operated HSM → Blockchain Network

Each layer performs a distinct role in the transaction lifecycle.

1. Institutional control
Transactions originate from the institution's controlled environment.

This can include:

  • core banking, treasury or other institutional systems;
  • authorised users and approvers; and
  • institution-managed network and firewall infrastructure.

The institution therefore retains its own governance around who can initiate and approve custody operations.

2. Secure connectivity
The institution connects to Bitpanda Custody through secured connectivity, such as a site-to-site VPN using an IPsec tunnel. This provides a protected communication path between the institution's infrastructure and the Bitpanda Custody environment.

3. Bitpanda Custody
Bitpanda Custody provides the integration and orchestration layer used to coordinate the custody transaction lifecycle.

GraphQL API

The GraphQL API provides the integration interface through which authorised client systems can interact with Bitpanda Custody.

Custody Services / Orchestration

Custody services coordinate transaction processing and the system processes required to move a transaction through the custody workflow.

Policy and Transaction Controls

Before final blockchain signing, transactions can be subject to configurable governance and transaction controls.

These can include:

Wallet Policy
Defines the applicable approval structure, including quorum and approval requirements.

Allow List
Restricts transactions to approved destinations where configured.

Threshold Rules
Apply value-based approval controls.

Time Delay
Introduces an additional review period before execution where configured.

These controls form part of the custody transaction workflow and operate before final cryptographic signing.

4. Bitpanda-Operated HSM

The Bitpanda-operated HSM provides the final cryptographic enforcement boundary.

Before custody-key use and final signing, the HSM validates:

  1. the transaction request;
  2. the applicable wallet policy;
  3. the required cryptographic approvals; and
  4. the authorised policy state.

Only after the required validations have succeeded can the relevant blockchain key be derived and used for final signing.

This separates access to the custody platform, transaction authorisation and final custody-key use.

5. Multi-Tenant and Dedicated HSM infrastructure

Two Bitpanda-operated HSM deployment approaches are available within the custodial model.

Multi-Tenant HSM Cluster

Multiple institutional clients can use shared HSM infrastructure with logical segregation of keys and policies between tenants. This provides managed and scalable custody infrastructure without requiring dedicated HSM hardware for each institution.

Dedicated HSM Cluster

A dedicated HSM environment can be allocated to an institution and operated by Bitpanda Custody. This provides additional physical and logical infrastructure isolation while retaining a Bitpanda-operated custody model.

6. Blockchain Networks

Following successful HSM validation and final signing, the signed transaction can proceed to the appropriate supported blockchain network.

The blockchain network then processes the signed transaction according to the rules of that network.

What control does the institution retain?

Using a custodial infrastructure model does not remove institutional governance over transaction activity.

The operating model can combine:

  • institutional user and access controls;
  • transaction initiation controls;
  • approval quorums;
  • wallet policies;
  • approved-destination controls;
  • value-based approval controls;
  • time delays; and
  • HSM-enforced cryptographic controls.

The result is a layered control model in which the institution governs authorised activity while Bitpanda operates the infrastructure responsible for final cryptographic signing.

Further information

For more information about transaction controls and cryptographic signing, see:

 

 

Was this article helpful?
0 out of 0 found this helpful