Custody-as-a-Service
Pronunciation: KUS-tuh-dee az ay SUR-vis
Definition
Custody-as-a-Service is a managed offering that provides custody capabilities such as wallet infrastructure, key control, policy workflows, transaction operations, and reporting to other businesses. Operations for Custody-as-a-Service should connect legal entitlement with the accounts, wallets, approvals, external balances, and records used to safeguard and return the assets. Reliable operation of Custody-as-a-Service requires clear authority, segregation, controlled withdrawals, provider continuity, and reconciliation between external assets and internal entitlements.
Overview
A business can integrate custody functions through APIs, hosted interfaces, dedicated infrastructure, or white-label products instead of building every component internally. Offerings range from technology-only deployments to arrangements where the service provider legally holds and administers client assets.
The service label does not identify the custody model. Customers must determine who holds keys or shares, who can approve transactions, which entity contracts with end users, and what licensing, segregation, insurance, and liability terms apply. Outsourced components can create concentration across many businesses.
Evaluation should cover assets, networks, deployment, key ceremonies, policy control, service levels, incident response, continuity, audits, data portability, sub-processors, and termination. Integration design must handle provider errors and delayed status safely. The customer remains responsible for aligning the service with its legal and operational obligations.
Records for Custody-as-a-Service should reconcile on-chain or provider balances with customer entitlements and the internal ledger by asset, network, account, and cutoff. For Custody-as-a-Service, pending deposits, locked assets, staking, fees, conversions, forks, unsupported transfers, and manual adjustments require separate treatment and review.
Custody-as-a-Service should be distinguished from investment ownership and from a software interface. For example, a provider may display an asset balance while holding pooled assets through another custodian; operations must verify contractual rights, segregation, withdrawal capability, and external evidence rather than rely on the screen alone.
For Custody-as-a-Service, risks include key compromise, insider abuse, commingling, inaccurate books, unsupported tokens, provider insolvency, sub-custodian failure, blocked withdrawals, lost recovery material, and ambiguous liability. For Custody-as-a-Service, controls should combine least privilege, separation of duties, verified destinations, asset segregation, limits, monitoring, and continuity tests.
Key Takeaway
Custody-as-a-Service accelerates deployment, but customers must verify whether they are buying technology, legal custody, or a combination of both.
Sources
- Ethereum Foundation Documentation: Accounts — Ethereum Foundation (2026-07-30)
- NIST Key Management Project — NIST (2026-08-02)