Custody & keys
Who controls keys? Review HSM/MPC boundaries, quorum, recovery, rotation and emergency access.
Evaluate custody, tokenization, payments, exchange and blockchain infrastructure with verifiable technical evidence rather than marketing claims.
Who controls keys? Review HSM/MPC boundaries, quorum, recovery, rotation and emergency access.
Where are transaction policies enforced and can one actor change critical policy or move assets?
Clarify SaaS, dedicated cloud, on-premise or hybrid requirements, data residency and network boundaries.
Require documented APIs, webhooks, idempotency, error models, sandbox/UAT and versioning.
Define KYC/KYB, AML/KYT, Travel Rule and third-party provider integration boundaries.
Review observability, audit, incident response, DR, RPO/RTO, rollback and handover.
Clarify source code, IP, data, keys and documentation ownership plus provider-exit procedures.
Ask for demos, sanitized architecture, test evidence, acceptance criteria and NDA-gated delivery artifacts.