trust and compliance
For compliance, risk and exam teams.
What Metal Custody does, what it doesn't, who is responsible for each control, and where it stands today. Written so your third-party risk review can start from facts rather than a sales deck.
at a glance
Your institution stays the custodian.
No vendor in the signing path
Metallicus holds no key share, runs no co-signer and hosts no policy server your signers depend on in a self-hosted deployment.
Keys in hardware you control
Signers use keys generated in your HSMs through PKCS#11. No single signer, server or person can move assets alone.
Every action is signed and recorded
Proposals, approvals, policy changes and releases are signed with passkeys and kept on a replicated, tamper-evident ledger your auditors can verify.
Dual control by default
Proposers can't approve their own payments; policy changes need several administrators and a waiting period; signers enforce their own limits.
Evidence on demand
A view-only role for examiners and auditors, guided procedures with sign-offs, and a one-click evidence pack with a hash manifest.
Built to be left
Your institution holds the keys and runs the software; an exit plan and source-code escrow are part of the licence discussion.
regulatory alignment
How it supports the guidance you're examined against.
Metal Custody is software; it doesn't make an activity permissible for your charter. Your counsel and regulators decide that. This is how the product supports each framework.
| Framework | How Metal Custody supports it |
|---|---|
| Fed, FDIC and OCC statement on crypto-asset safekeeping (July 2025) | Keys generated and held under the institution's control; no other party can unilaterally transfer; governance, audit coverage of key generation, storage and transfer; documented contingency and recovery. |
| OCC interpretive letters 1170, 1172, 1183, 1184 | Supports bank-run custody and customer-directed transactions with dual control, limits and records; outsourcing models are described with their third-party-risk implications. |
| NCUA letters 21-CU-16 and 22-CU-07 | Due-diligence materials, a shared-responsibility matrix and a control map for state-chartered credit unions; the site notes that federal credit unions aren't currently authorized to custody digital assets. |
| Interagency third-party risk guidance (2023) | A due-diligence pack, a 150-question security questionnaire, business continuity and disaster recovery, and an exit plan; examiner access to evidence without vendor involvement. |
| FFIEC IT Examination Handbook | Controls mapped across Information Security, Business Continuity, Architecture, Infrastructure and Operations, and Outsourcing Technology Services. |
| BSA/AML, OFAC and the Travel Rule | Sanctions screening on new addresses and payments, Travel Rule data capture with access controls, and screening evidence in the audit record. Your BSA program remains yours. |
| SOC 2 Trust Services Criteria | Controls mapped to CC1–CC9, availability and confidentiality, with a readiness plan toward a product-scoped Type II report. |
current status
Where it stands, stated plainly.
| Item | Status | Detail |
|---|---|---|
| Independent security audit | Pending | Internal adversarial reviews of the signing core and the API were completed in September 2026; findings are being remediated before engaging an independent firm. |
| Penetration test | Pending | To be performed by an independent firm; results shared with institutions under NDA. |
| SOC 2 | Company level | Metallicus completed a company-level SOC 2 Type I in August 2026: a point-in-time review of control design, not an opinion on Metal Custody. A product-scoped Type II is planned. |
| Hardware security modules | In progress | PKCS#11 support is built and tested; a cloud HSM trial is under way. The live demonstration uses encrypted key files. |
| Recovery drill | Tested | Scripted loss and restore of a signer and a ledger site, run in a test environment; to be repeated with an institution's people and hardware. |
| Live demonstration | Running | End to end on Metal mainnet: approval sites on three continents, independent signers, passkey approvals. |
shared responsibility
Who does what.
| Area | Your institution | Metallicus |
|---|---|---|
| Keys and HSMs | Owns and controls | Provides the software and procedures |
| Approvals and policy | Sets people, limits and rules | Enforces them in the software |
| BSA/AML and OFAC programs | Owns the program and decisions | Provides screening and Travel Rule tooling |
| Servers and operations | Self-hosted: yours. Managed: oversight | Managed: runs servers, updates and monitoring (next) |
| Software security | Reviews and accepts releases | Secure development, fixes, advisories |
| Charter and permissibility | Counsel and regulators decide | Supplies facts for the analysis |
due-diligence pack
Available to institutions on request.
Shared under NDA with institutions evaluating Metal Custody.
- Control matrixAbout 75 controls mapped to the joint statement, OCC, FFIEC, NCUA, SOC 2 and NIST CSF, with evidence and owners.
- Security questionnaire150 pre-answered questions in the SIG Lite and CAIQ style.
- Shared-responsibility matrixPer deployment model: self-hosted, managed, member wallet, stablecoin issuer.
- Architecture and data flowsTrust boundaries, what data lives where, retention and encryption.
- Business continuity, recovery and exit planRecovery objectives per component, drill evidence, escrow options.
- Examiner walkthroughStep-by-step tests of key controls using the evidence pack and view-only access.
- Security review reportsFindings and remediation status; independent reports when available.
- Questions for counselA brief to help your legal review of each deployment model.
Talk to us before your review starts.
We'll walk your compliance, risk and technology teams through the controls, the evidence and the open items, and share the pack.