trust and compliance

For compliance, risk and exam teams.

What Metal Custody does, what it doesn't, who is responsible for each control, and where it stands today. Written so your third-party risk review can start from facts rather than a sales deck.

at a glance

Your institution stays the custodian.

No vendor in the signing path

Metallicus holds no key share, runs no co-signer and hosts no policy server your signers depend on in a self-hosted deployment.

Keys in hardware you control

Signers use keys generated in your HSMs through PKCS#11. No single signer, server or person can move assets alone.

Every action is signed and recorded

Proposals, approvals, policy changes and releases are signed with passkeys and kept on a replicated, tamper-evident ledger your auditors can verify.

Dual control by default

Proposers can't approve their own payments; policy changes need several administrators and a waiting period; signers enforce their own limits.

Evidence on demand

A view-only role for examiners and auditors, guided procedures with sign-offs, and a one-click evidence pack with a hash manifest.

Built to be left

Your institution holds the keys and runs the software; an exit plan and source-code escrow are part of the licence discussion.

regulatory alignment

How it supports the guidance you're examined against.

Metal Custody is software; it doesn't make an activity permissible for your charter. Your counsel and regulators decide that. This is how the product supports each framework.

FrameworkHow Metal Custody supports it
Fed, FDIC and OCC statement on crypto-asset safekeeping (July 2025)Keys generated and held under the institution's control; no other party can unilaterally transfer; governance, audit coverage of key generation, storage and transfer; documented contingency and recovery.
OCC interpretive letters 1170, 1172, 1183, 1184Supports bank-run custody and customer-directed transactions with dual control, limits and records; outsourcing models are described with their third-party-risk implications.
NCUA letters 21-CU-16 and 22-CU-07Due-diligence materials, a shared-responsibility matrix and a control map for state-chartered credit unions; the site notes that federal credit unions aren't currently authorized to custody digital assets.
Interagency third-party risk guidance (2023)A due-diligence pack, a 150-question security questionnaire, business continuity and disaster recovery, and an exit plan; examiner access to evidence without vendor involvement.
FFIEC IT Examination HandbookControls mapped across Information Security, Business Continuity, Architecture, Infrastructure and Operations, and Outsourcing Technology Services.
BSA/AML, OFAC and the Travel RuleSanctions screening on new addresses and payments, Travel Rule data capture with access controls, and screening evidence in the audit record. Your BSA program remains yours.
SOC 2 Trust Services CriteriaControls mapped to CC1–CC9, availability and confidentiality, with a readiness plan toward a product-scoped Type II report.

current status

Where it stands, stated plainly.

ItemStatusDetail
Independent security auditPendingInternal adversarial reviews of the signing core and the API were completed in September 2026; findings are being remediated before engaging an independent firm.
Penetration testPendingTo be performed by an independent firm; results shared with institutions under NDA.
SOC 2Company levelMetallicus completed a company-level SOC 2 Type I in August 2026: a point-in-time review of control design, not an opinion on Metal Custody. A product-scoped Type II is planned.
Hardware security modulesIn progressPKCS#11 support is built and tested; a cloud HSM trial is under way. The live demonstration uses encrypted key files.
Recovery drillTestedScripted loss and restore of a signer and a ledger site, run in a test environment; to be repeated with an institution's people and hardware.
Live demonstrationRunningEnd to end on Metal mainnet: approval sites on three continents, independent signers, passkey approvals.

shared responsibility

Who does what.

AreaYour institutionMetallicus
Keys and HSMsOwns and controlsProvides the software and procedures
Approvals and policySets people, limits and rulesEnforces them in the software
BSA/AML and OFAC programsOwns the program and decisionsProvides screening and Travel Rule tooling
Servers and operationsSelf-hosted: yours. Managed: oversightManaged: runs servers, updates and monitoring (next)
Software securityReviews and accepts releasesSecure development, fixes, advisories
Charter and permissibilityCounsel and regulators decideSupplies facts for the analysis

due-diligence pack

Available to institutions on request.

Shared under NDA with institutions evaluating Metal Custody.

  • Control matrixAbout 75 controls mapped to the joint statement, OCC, FFIEC, NCUA, SOC 2 and NIST CSF, with evidence and owners.
  • Security questionnaire150 pre-answered questions in the SIG Lite and CAIQ style.
  • Shared-responsibility matrixPer deployment model: self-hosted, managed, member wallet, stablecoin issuer.
  • Architecture and data flowsTrust boundaries, what data lives where, retention and encryption.
  • Business continuity, recovery and exit planRecovery objectives per component, drill evidence, escrow options.
  • Examiner walkthroughStep-by-step tests of key controls using the evidence pack and view-only access.
  • Security review reportsFindings and remediation status; independent reports when available.
  • Questions for counselA brief to help your legal review of each deployment model.

Talk to us before your review starts.

We'll walk your compliance, risk and technology teams through the controls, the evidence and the open items, and share the pack.