Bitpanda Enterprise Custody supports a custodial operating model in which Bitpanda operates the cryptographic infrastructure responsible for custody-key protection and final blockchain signing.
The institution retains governance over its users, transaction initiation and configured approval processes, while Bitpanda Custody provides the transaction orchestration, configurable policy controls and HSM infrastructure required to execute authorised blockchain transactions.
This creates a separation between institutional transaction governance and operation of the underlying cryptographic infrastructure.
Architecture overview
At a high level, the transaction flow is:
Institution → Secure Connectivity → Bitpanda Custody → Bitpanda-Operated HSM → Blockchain Network
Each layer performs a distinct role in the transaction lifecycle.
1. Institutional control
Transactions originate from the institution's controlled environment.
This can include:
- core banking, treasury or other institutional systems;
- authorised users and approvers; and
- institution-managed network and firewall infrastructure.
The institution therefore retains its own governance around who can initiate and approve custody operations.
2. Secure connectivity
The institution connects to Bitpanda Custody through secured connectivity, such as a site-to-site VPN using an IPsec tunnel. This provides a protected communication path between the institution's infrastructure and the Bitpanda Custody environment.
3. Bitpanda Custody
Bitpanda Custody provides the integration and orchestration layer used to coordinate the custody transaction lifecycle.
GraphQL API
The GraphQL API provides the integration interface through which authorised client systems can interact with Bitpanda Custody.
Custody Services / Orchestration
Custody services coordinate transaction processing and the system processes required to move a transaction through the custody workflow.
Policy and Transaction Controls
Before final blockchain signing, transactions can be subject to configurable governance and transaction controls.
These can include:
Wallet Policy
Defines the applicable approval structure, including quorum and approval requirements.
Allow List
Restricts transactions to approved destinations where configured.
Threshold Rules
Apply value-based approval controls.
Time Delay
Introduces an additional review period before execution where configured.
These controls form part of the custody transaction workflow and operate before final cryptographic signing.
4. Bitpanda-Operated HSM
The Bitpanda-operated HSM provides the final cryptographic enforcement boundary.
Before custody-key use and final signing, the HSM validates:
- the transaction request;
- the applicable wallet policy;
- the required cryptographic approvals; and
- the authorised policy state.
Only after the required validations have succeeded can the relevant blockchain key be derived and used for final signing.
This separates access to the custody platform, transaction authorisation and final custody-key use.
5. Multi-Tenant and Dedicated HSM infrastructure
Two Bitpanda-operated HSM deployment approaches are available within the custodial model.
Multi-Tenant HSM Cluster
Multiple institutional clients can use shared HSM infrastructure with logical segregation of keys and policies between tenants. This provides managed and scalable custody infrastructure without requiring dedicated HSM hardware for each institution.
Dedicated HSM Cluster
A dedicated HSM environment can be allocated to an institution and operated by Bitpanda Custody. This provides additional physical and logical infrastructure isolation while retaining a Bitpanda-operated custody model.
6. Blockchain Networks
Following successful HSM validation and final signing, the signed transaction can proceed to the appropriate supported blockchain network.
The blockchain network then processes the signed transaction according to the rules of that network.
What control does the institution retain?
Using a custodial infrastructure model does not remove institutional governance over transaction activity.
The operating model can combine:
- institutional user and access controls;
- transaction initiation controls;
- approval quorums;
- wallet policies;
- approved-destination controls;
- value-based approval controls;
- time delays; and
- HSM-enforced cryptographic controls.
The result is a layered control model in which the institution governs authorised activity while Bitpanda operates the infrastructure responsible for final cryptographic signing.
Further information
For more information about transaction controls and cryptographic signing, see:
- Understanding Custodial and Non-Custodial Deployment Models
- How Transaction Authorisation and Blockchain Signing Are Separated
- What is an HSM?
- What is quorum approval?
- BE Custody Wallet Capabilities, Spending Rules, and Threshold Sending Rules