The keys never leave the bank.

The infrastructure runs inside the institution and under its control. Neither the keys nor its clients’ data leave its perimeter.

Where each element stays

ElementHow it is handledWhere it stays
Client keysThey are generated and held in the bank’s HSMs, physical or in its cloud. Finhattan has no access to them.At the bank
Chain of the assetsThe bank does not add a third-party custodian between its clients and their assets.At the bank
DataClient and transaction data are processed and stored on the institution’s infrastructure.At the bank
Product and marginThe bank decides what it offers, to whom and on what terms, under its brand and in its app.At the bank
TransparencyThe bank and its auditors can review the technology running on its infrastructure.At the bank

Experience in cryptographic systems

  • Secure communicationsOur team comes from secure communications engineering, with more than thirty years of R&D in encryption systems and national security communications.
  • Key management and signingWe have built our own wallet technology: key generation and custody and on-chain transaction signing, without ever exposing the keys.
  • The bank’s HSMsThe infrastructure is designed to sign inside the hardware security modules (HSMs) the bank already uses, whether physical or deployed in its cloud. The level of protection is the same in both cases.

Audits and assurances

The code and the deployed infrastructure can undergo the reviews the institution and its supervisor require, for its peace of mind and its regulator’s.

ReviewHow it is doneWhy it matters to the bank
Code reviewThe bank, or a third party it appoints, can review the core code under a confidentiality agreement.Knowing exactly what runs on its infrastructure.
Penetration testingIndependent tests on the deployed infrastructure, with a report and a dated remediation plan.Evidence for its risk committee.
Smart contract auditThe on-chain contracts deployed are audited by specialised independent firms before going into production.Assurance over the logic that operates on its clients’ assets.
Information securityControls that can be assessed against the frameworks the institution requires, such as ISO/IEC 27001.Answering the bank’s vendor questionnaire.
Operational resilience (DORA)Audit and access rights, supervisory inspection, incident reporting and a documented exit strategy.Meeting its obligations towards its technology providers.
ContinuityBusiness continuity and recovery plan with documented tests.A service prepared for any contingency.
Source code escrowThe intellectual property belongs to Finhattan, and the source code is deposited with an independent agent, with access for the bank under the agreed circumstances.The confidence of relying on critical infrastructure with full legal certainty.

Let’s talk about your institution.

Request a meeting