Custody for any asset enhanced with the best in class tokenization stack on the complete enterprise digital asset platform.
Request a demo
Enterprise custody is no longer just about secure storage, it’s about flexibility, control, and confidence.
Kaleido Custody provides the programmable security framework so you can build an institutional-grade custody solution that scales with your business and meets your customers’ needs.
No. Kaleido Custody does not generate or hold private keys on your behalf. Keys are created inside the keystore you choose, and with an HSM that means inside the hardware boundary. If you run the platform on-premise, you can block Kaleido from ever reaching your key material, while the Remote Signing Module next to your HSM enforces policy before each signature.
Kaleido Custody works natively with seven HSMs and keystores: Thales Luna, IBM OSO, Fortanix, AWS CloudHSM, GCP Cloud HSM, Azure Key Vault and HashiCorp Vault. For any other PKCS#11-compliant HSM, you deploy Kaleido's Remote Signing Module next to the device and connect it the same way. The Remote Signing Module also enforces your signing policies before the HSM signs.
Kaleido Custody enforces policies at the signing layer, before the HSM signs anything. You write policies as code in Rego on the Open Policy Agent standard, and they run in the Remote Signing Module alongside your HSM. A policy can check amount, velocity, counterparty, screening results or time of day, and any new policy version needs approval before it takes effect.
Kaleido Custody supports maker/checker, four-eye approval, ordered multi-level chains and quorum approval, where a minimum number of approvers must sign off. Each rule can depend on the asset, the wallets involved, the chain or the transaction value. Every approval, policy decision and signature lands in an audit log your team can query by API.
Yes. Kaleido Custody supports hot, warm, cold and air-gapped wallets side by side, along with omnibus wallets and deposit and withdrawal pools. For offline signing, the payload travels by QR code or secure portable storage, and the Remote Signing Module checks that it hasn't been tampered with before the key signs.
Yes. Kaleido Custody runs three ways. Kaleido can host it as fully managed SaaS, or your team can host the whole platform on your own Kubernetes infrastructure. In the hybrid model, Kaleido runs the platform while you host the Remote Signing Module next to your own HSM, so keys and signing policy stay in your environment.
