Custody //
Digital Assets

Institutional-grade custody for real-world assets & crypto

Custody for any asset enhanced with the best in class tokenization stack on the complete enterprise digital asset platform.

Request a demo

Wallet infrastructure that easily scales to millions of secure accounts

Enterprise custody is no longer just about secure storage, it’s about flexibility, control, and confidence.

Kaleido Custody provides the programmable security framework so you can build an institutional-grade custody solution that scales with your business and meets your customers’ needs.

Programmable policy and compliance engine
Automate policies, enforce business rules, and maintain a full audit trail of your on and off-chain activities and policy decisions.
Out of the box HSM support
Connect to your enterprise HSM or secure trusted key storage approved by your risk and compliance teams.
Customizable workflow engine for digital assets
Rapidly tailor your own workflows and connect to your internal systems.

A full spectrum of leading keystores

• Leverage scalable & encrypted Kaleido HD wallets
• Integrate with your existing HSM providers
• Plug into your own custom key management solution
• Remote policy enforcement deployed alongside trusted enterprise keystores
• Avoid costly signature errors through verifiable tamperproof payload signatures

Powerful wallet configurations

Support for any wallet configuration so you can build the custody architecture that fits your strategy.
‍
• Online or offline
• Hot, warm, cold wallet
• Omnibus wallets ready for retail deposits
• Deposit and withdrawal pool management

Programmable workflows and policies for any asset

Kaleido's Platform is built for builders. Create workflows that govern deposits, transfers, subscriptions, and withdrawals for any tokenized asset.

Define custom approval logic, limit thresholds, and sweeping rules across wallets and assets so your business processes are enforced without fail.

Plug into your existing security architecture

• Plug into your existing enterprise systems
• Craft security and compliance rules for digital assets value movement
• Integrate with existing identity systems  
• Customize role-based access controls for different business units

The first custody solution with native support for privacy-preserving tokens

Interact with zk and confidential tokens, tracking swaps within private execution groups, just like any other public asset.

Manage business operations in a 
purpose-built experience tailored to 
digital asset activities

A purpose-built operations experience for digital assets. Integrated approval queues and configurable policies give operators confidence that every interaction involves trusted assets and wallets with a complete audit trail.

• Real-time balances and balance changes
• Configurable omnibus pools
• Transaction approval notifications via web or mobile

Enterprise-grade policy engine

Build policies to the OPA open industry standard with the most flexible and programmable experience. Apply rules at the edge, inside trusted execution environments for real-time compliance.

Write your own policy, or leverage one of Kaleido's out of the box policies in areas such as:
• Four-eyes approval
• Simple and tiered transfer limits
• Executive sign-off
• KYC and KYT transaction screening

An omni-asset Custody solution

Stablecoins

Manage institutional-grade stablecoins with automated minting, burning, and reporting workflows.

Native tokens

Index balances and enable asset lifecycle operations for native tokens across EVM and non-EVM chains, including Bitcoin, Ethereum, Solana and more.

Collateral & RWAs

Safeguard tokenized collateral and real-world assets (RWAs) with programmable enforcement and multi-keystore support.

Tokenized Deposits

Securely issue and manage programmable deposits with full-spectrum key and policy controls.

CBDCs

Institutional-grade custody with sovereign key management and a programmable policy engine to securely manage digital sovereign money.

Securities

Safeguard underlying assets and securely manage the entire lifecycle of the asset, from issuance to distribution.

Frequently asked questions

What your legal, risk, and technology teams may ask.

Does Kaleido ever hold our private keys?

No. Kaleido Custody does not generate or hold private keys on your behalf. Keys are created inside the keystore you choose, and with an HSM that means inside the hardware boundary. If you run the platform on-premise, you can block Kaleido from ever reaching your key material, while the Remote Signing Module next to your HSM enforces policy before each signature.

Which HSMs does Kaleido Custody support?

Kaleido Custody works natively with seven HSMs and keystores: Thales Luna, IBM OSO, Fortanix, AWS CloudHSM, GCP Cloud HSM, Azure Key Vault and HashiCorp Vault. For any other PKCS#11-compliant HSM, you deploy Kaleido's Remote Signing Module next to the device and connect it the same way. The Remote Signing Module also enforces your signing policies before the HSM signs.

Where are custody policies enforced?

Kaleido Custody enforces policies at the signing layer, before the HSM signs anything. You write policies as code in Rego on the Open Policy Agent standard, and they run in the Remote Signing Module alongside your HSM. A policy can check amount, velocity, counterparty, screening results or time of day, and any new policy version needs approval before it takes effect.

What approval workflows can we set up?

Kaleido Custody supports maker/checker, four-eye approval, ordered multi-level chains and quorum approval, where a minimum number of approvers must sign off. Each rule can depend on the asset, the wallets involved, the chain or the transaction value. Every approval, policy decision and signature lands in an audit log your team can query by API.

Can we run hot, warm and cold wallets on one platform?

Yes. Kaleido Custody supports hot, warm, cold and air-gapped wallets side by side, along with omnibus wallets and deposit and withdrawal pools. For offline signing, the payload travels by QR code or secure portable storage, and the Remote Signing Module checks that it hasn't been tampered with before the key signs.

Can we deploy Kaleido Custody in our own environment?

Yes. Kaleido Custody runs three ways. Kaleido can host it as fully managed SaaS, or your team can host the whole platform on your own Kubernetes infrastructure. In the hybrid model, Kaleido runs the platform while you host the Remote Signing Module next to your own HSM, so keys and signing policy stay in your environment.

Explore our other product lines:

Web3 Middleware

Seamlessly handle sophisticated transaction and event orchestration for your digital asset workflows leveraging Kaleido’s Web3 Middleware, rooted in the leading open source project for enterprises building on blockchain.
Learn more

Chain Infrastructure

Deploy and scale production-ready blockchain networks on your protocol of choice with enterprise-grade security, 99.99% uptime SLAs, and automated lifecycle management across any cloud, hybrid, or on‑prem environment.
Learn more

A platform for any digital asset & any use case

From tokenized securities and RWAs to stablecoins and deposits, our platform provides a single, unified foundation for your entire digital asset strategy.

Any asset

Stablecoins
Tokenized deposits
Tokenized funds
CBDCs
Digital securities
Commodities
Bonds
+ more

Any use case

Cross-border payments
Treasury management
Trade finance
Traceability
Foreign exchange
Remittance
Digital money issuance
+ more

Kaleido is the #1 digital asset and blockchain platform on G2

Learn why companies ranging from large global institutions to cutting-edge start-ups have chosen Kaleido as the #1 asset tokenization and blockchain as a service provider.
Ranked #1 Asset Tokenization Platform on G2
Ranked #1 Blockchain-aaS Platform on G2
NSF Logo
Blockchain Interoperability Grant Winner
Blockchain research institute logo
Enterprise Blockchain
Award Winner