for banks and credit unions
Offer digital-asset services under your institution's control.
Metal Custody is self-hosted software for approving and signing digital-asset transactions with your own people, hardware and keys. Metallicus cannot sign. See a live payment on Metal mainnet, then scope what deployment would take at your institution.
Live end-to-end demonstration on Metal mainnet. Independent product audit and penetration test pending.
use cases
Three ways institutions put it to work.
Your own digital dollar
Minting, burning, freezing and pausing an institution-branded stablecoin each need your own approvals, with limits your signers enforce.
- Owner
- Treasury and issuance
- Control
- No single person can mint
Assets members and customers ask about
Hold Bitcoin, Ethereum and stablecoins for members or customers, where your charter and regulators permit it, instead of sending them elsewhere.
- Owner
- Digital-asset operations
- Control
- Approved destinations and limits
Institutional wallets
Settlement, liquidity and operating wallets with dual control, per-signer caps, and a record your auditors can review.
- Owner
- Treasury and finance
- Control
- Separate proposers and approvers
Coming from the Stablecoin Pilot? The pilot requires no custody of digital assets. Metal Custody is the step when your institution takes custody on itself.
why institution-owned
Keep control inside your institution.
When a bank safekeeps a crypto-asset, the Federal Reserve, FDIC and OCC describe control as being able to show that no other party, including the customer, can unilaterally transfer it (July 2025 statement). The statement adds no new requirement, and it does not apply to credit unions.
Metal Custody is built so an institution can make that showing without a vendor key share, co-signer or policy server in the way. Whether your charter permits a given activity is for your counsel and regulators: NCUA currently does not authorize federal credit unions to custody digital assets, and state-chartered authority depends on state law.
how a payment works
No one person can complete a payment.
- 01
Proposed
Only to an address your institution has already approved, and signed by the proposer with a passkey.
- 02
Approved
By someone else, with more approvers as the amount rises. Face ID, Touch ID or a security key.
- 03
Signed
Your approval sites agree it still meets policy, your hardware signs, and the record stays for your examiners and auditors.

security model
Assets move only when your people and your hardware agree.
Metallicus cannot sign
No vendor key share, no co-signer and no vendor server your signers depend on. The operator of a managed deployment gets no signing share either.
Keys in your hardware
Each production key is generated in an HSM your institution controls and cannot be exported. The live demonstration uses encrypted key files.
Independent checks
Approvals, policy checks and each signer are separate, and are designed so that one compromised component cannot authorize a transfer.
Controls over the controls
Adding people or loosening limits needs several administrators and a waiting period, and every signer verifies the change.
Approved destinations
New addresses need a second person. Removing one takes effect at once and stops payments to it that are still waiting.
Limits and stop
Per-signer caps per asset, per payment and per day, whatever the approvals. Any approver can stop new outbound transfers from a wallet.
Established multi-party accounts on each network: native multisig on Bitcoin, Litecoin and Dogecoin; Safe smart-contract accounts on Ethereum and EVM networks, which your governance should review as it would any smart contract.
integration and operations
Works alongside your core. It doesn't replace it.
- Wallets, approvals, policy and signing
- The console for staff on desktop and phone
- An audit record of every step
- Issuer controls for your stablecoin
- Posting to your core and digital banking
- Reconciliation and general-ledger files
- Sanctions screening and Travel Rule data
- Member or customer statements
- Customer records, BSA/AML and OFAC programs
- People who propose and approve
- HSMs, sites and recovery exercises
- Charter and regulatory permissibility
Core and digital-banking integrations are designed with each institution; we'll tell you what exists today and what would be built for you.
deployment
Run it yourself, or let Metallicus or your CUSO run it. Your institution holds the keys.
Self-hosted
Your team runs the approval sites and signers in your data centers and cloud accounts, with your HSMs.
- Keys
- Your institution
- Operations
- Your institution
Managed
Metallicus or your CUSO runs the servers, updates and monitoring. Your keys stay in your HSMs. The operator gets no signing share.
- Keys
- Your institution
- Operations
- Metallicus or your CUSO
| Question | Custody-as-a-service | Metal Custody |
|---|---|---|
| Who runs it | The provider | Your institution, or an operator you choose |
| Provider in the signing path | Usually, through a key share or co-signer | No |
| Where approvals are decided | The provider's policy server | Your own approval sites |
| If Metallicus is gone | Varies; often a provider tool | You still hold the keys, and payments don't need our approval |
Enterprise licensing and implementation are scoped to your networks, HSMs, approval sites, integrations and support, and quoted in the briefing. A fully hosted offer, where a chartered custodian holds the keys, would be a separate, later product.
pilot to production
From a live walkthrough to an approved deployment.
- 01
Live walkthrough
A real payment on Metal mainnet for your CEO, CFO, technology lead and BSA officer.
- 02
Scoped evaluation
Your networks, use cases, integrations and staffing, in your own environment.
- 03
Security and compliance review
Charter and legal review, independent testing, third-party risk, BSA/AML and OFAC.
- 04
Approved deployment
HSM setup, key ceremony, recovery exercises and operating procedures, then go live.
networks and assets
Your own digital dollar, and the assets members already ask you to hold.
For institution-branded stablecoins, issuer controls put minting, burning, freezing and pausing under your own approvals.
- BitcoinAvailable
- Ethereum and EVM networksAvailable
- Stablecoins and tokensAvailable
- Stablecoin issuer controlsAvailable
Litecoin and Dogecoin are also available. XRP, Solana and XPR Network are planned. Live demo: running today on Metal mainnet. Available: built and tested, brought live in each institution's deployment.
faq
Questions before custody rollout.
Can Metallicus move our assets?
No. Metallicus holds no key and runs no signer. In a self-hosted deployment it runs no approval site either. Every payment needs your people's approvals and your signers.
Does our charter allow this?
This site doesn't decide that; your counsel and regulators do. NCUA currently does not authorize federal credit unions to custody digital assets, and state-chartered authority depends on state law. The Stablecoin Pilot is a path that requires no custody.
Has Metal Custody been independently audited?
Not yet. An independent security audit and penetration test are pending, and we will share results as they become available. Separately, Metallicus completed a company-level SOC 2 Type I in August 2026: a point-in-time review of company control design, not an opinion on Metal Custody and not a Type II test of controls in operation.
What would our staff need to run?
Approval sites, signers with HSMs, and the people who propose and approve. The managed option, next on our roadmap, moves servers, updates and monitoring to Metallicus or your CUSO while your institution keeps the keys.
Does it connect to our core?
It works alongside your core and doesn't replace it. Posting to the core and to digital banking is scoped with each institution.
What if Metallicus is gone?
You still hold the keys, and payments don't need our approval. Support is a contract you can end without moving your assets.
See a live payment approved and signed.
A 30-minute walkthrough of a live payment on Metal mainnet, what deployment would require at your institution, and a diligence checklist for your team.
Live demo