The keys never leave the bank.
The infrastructure runs inside the institution and under its control. Neither the keys nor its clients’ data leave its perimeter.
Where each element stays
| Element | How it is handled | Where it stays |
|---|---|---|
| Client keys | They are generated and held in the bank’s HSMs, physical or in its cloud. Finhattan has no access to them. | At the bank |
| Chain of the assets | The bank does not add a third-party custodian between its clients and their assets. | At the bank |
| Data | Client and transaction data are processed and stored on the institution’s infrastructure. | At the bank |
| Product and margin | The bank decides what it offers, to whom and on what terms, under its brand and in its app. | At the bank |
| Transparency | The bank and its auditors can review the technology running on its infrastructure. | At the bank |
Experience in cryptographic systems
- Secure communicationsOur team comes from secure communications engineering, with more than thirty years of R&D in encryption systems and national security communications.
- Key management and signingWe have built our own wallet technology: key generation and custody and on-chain transaction signing, without ever exposing the keys.
- The bank’s HSMsThe infrastructure is designed to sign inside the hardware security modules (HSMs) the bank already uses, whether physical or deployed in its cloud. The level of protection is the same in both cases.
Audits and assurances
The code and the deployed infrastructure can undergo the reviews the institution and its supervisor require, for its peace of mind and its regulator’s.
| Review | How it is done | Why it matters to the bank |
|---|---|---|
| Code review | The bank, or a third party it appoints, can review the core code under a confidentiality agreement. | Knowing exactly what runs on its infrastructure. |
| Penetration testing | Independent tests on the deployed infrastructure, with a report and a dated remediation plan. | Evidence for its risk committee. |
| Smart contract audit | The on-chain contracts deployed are audited by specialised independent firms before going into production. | Assurance over the logic that operates on its clients’ assets. |
| Information security | Controls that can be assessed against the frameworks the institution requires, such as ISO/IEC 27001. | Answering the bank’s vendor questionnaire. |
| Operational resilience (DORA) | Audit and access rights, supervisory inspection, incident reporting and a documented exit strategy. | Meeting its obligations towards its technology providers. |
| Continuity | Business continuity and recovery plan with documented tests. | A service prepared for any contingency. |
| Source code escrow | The intellectual property belongs to Finhattan, and the source code is deposited with an independent agent, with access for the bank under the agreed circumstances. | The confidence of relying on critical infrastructure with full legal certainty. |
Further reading
- Physical or cloud HSM to safeguard digital assetsPhysical or cloud HSM for digital asset custody in a bank: signing inside the module, policies, DORA and the criteria for choosing a deployment.
- MiCA and DORA: what changes for a bank that wants to offer digital assetsMiCA and DORA for banks: Article 60 notification, crypto-asset custody, stablecoins, ICT third-party risk, audit rights and exit strategies.