Custody and wallet architecture
We work through where keys live, who controls them, and what the chosen model commits you to for years.
Senior advisory for institutions and operators whose custody, settlement, and tokenization decisions span several systems, several vendors, and more than one team.
Advisory scope
We connect custody, vendor, operational, and governance decisions across the program.
We work through where keys live, who controls them, and what the chosen model commits you to for years.
We assess which controls remain with you and which depend on the vendor.
We define who runs what, which procedures have to exist, and what evidence the program produces as it operates.
We sequence decisions and readiness checks for launch, migration, and external review.
Timing
Several systems or vendors need one security view.
An institution is entering or growing digital assets.
Leadership needs challenge across multiple workstreams.
Technical, operational, and governance questions cannot be separated.
Our approach
Agree the products, operating model, risk appetite, and stakeholders. Set the criteria for comparing architecture, custody, and vendor options.
Document how vendors, systems, and operations connect. Identify inherited trust assumptions, failure scenarios, and gaps in control ownership.
Assess each option against the agreed criteria. Document its costs, risks, and control owners in a decision framework.
Sequence security priorities and dependencies in executive and technical sessions. Set owners and decision points for delivery.
What you receive
The options, what each one costs you, and who ends up owning the control.
How vendors, systems, and operations connect.
Security priorities in order, worked through in executive and technical sessions.
Your engagement team
A principal leads each engagement. Your proposal names the specialists assigned to the scope.
Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
Principal Advisor
Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.
FAQ
A review takes one system and examines it. This takes the program: several systems, several vendors, and the decisions that cross between them. Advisory work usually identifies which reviews are worth running, and when.
We advise, design, and review. We do not operate your program and we do not resell custody or security platforms, which is what lets us assess a vendor without holding a stake in the answer.
No. That is one of the more common starting points. The questions simply move to integration, operating model, key ceremony design, role separation, and what your exit looks like if the relationship ends.
Usually more than one function: engineering, operations, risk or compliance, and someone who can decide when those three disagree. Include the people who can approve decisions across these functions.
Yes. A custody model, vendor choice, integration, or migration can be the starting point. We consider the dependencies relevant to that decision and agree how far the advisory scope extends.
Describe the program, open decisions, and deadline. We will define the advisory scope.
Discuss your scope