Institutional custody with MPC: what it means for your company's balance
Institutional custody with MPC splits the key that moves a balance into fragments, so the full key never exists in one place. It reduces theft and individual error, but it does not remove your dependence on the provider.
When a company leaves operating cash on a digital-asset platform, the uncomfortable question is not how the money moves but who controls the key that moves it. It is a treasury question, not a technology one, and it seldom reaches the finance committee before signing.
At Soulbit Academy we explain what institutional custody with MPC means for a company's balance, with equal rigour on what it protects and what it leaves open. Soulbit is a custodial platform: clients do not manage keys. Below we describe how that model works, where it stops and which questions you should put to any provider, Soulbit included.
What institutional custody is and why the company does not manage the keys
Institutional custody is the model in which a specialised entity holds the private keys of the wallets and signs movements on the client's behalf. With a digital asset, whoever controls the key controls the balance. In a custodial model, that control sits with the custodian, not with the client company.
This must be clear from the start, because it is sometimes confused with other arrangements. Soulbit is custodial: the company neither holds nor manages keys, so it cannot lose them. In exchange, it depends on the provider and its custodian operating well and meeting their obligations.
For an SME with a small finance team, the operational benefit is real. Nobody has to safeguard recovery phrases or signing devices, and an employee leaving does not strand a key. A specialised function is delegated and a relationship of trust is accepted.
That trust is counterparty risk. We cover it in counterparty risk: how to assess who you trust with your balance, and here we pick it up from the custody angle. For the wider product picture, see what Soulbit is and how it works for an SME.
How MPC custody works: a key that never exists in full
MPC custody (multi-party computation) divides the key into fragments that are generated and used in different places, so the complete key never exists in one location. To sign a transaction, the fragments cooperate through a cryptographic protocol without coming together. The outcome is a valid signature, not a reassembled key.
The difference from a classic setup is structural. A traditional wallet has one key, and whoever obtains it can move the entire balance. In MPC there is no such single point. An attacker, or a disloyal employee, would need to compromise several separate fragments at once.
No individual, whether at Soulbit or at the custodian, ever sees a complete key. That is the property a CFO should care about: one person's mistake or bad intent is not enough, on its own, to empty a balance.
MPC is backed by public cryptographic research. The US National Institute of Standards and Technology runs a project called Multi-Party Threshold Cryptography, which develops schemes to distribute trust in the operation of cryptographic primitives such as digital signatures, with a view to possible standardisation. It is the conceptual basis of what we describe.
Is MPC the same as having several people approve a payment?
No. MPC spreads the cryptographic key across fragments; it does not define who approves a payment inside the company. A multi-signer approval workflow is a separate business control. Soulbit does not claim client-configurable approval flows today. If that control is essential to your policy, ask about it and verify the answer in writing.
What MPC custody mitigates on your balance and what it does not
MPC custody mitigates two specific risks, theft of a single key and the error of one person, and it does not mitigate the risks that depend on the entity, on regulation or on the stablecoin issuer. Separating the two lists avoids the most common confusion: believing a signing technology replaces counterparty analysis.
The first risk it mitigates is theft of a single key, because that key does not exist. The second is the error or bad faith of an individual, because no one sees the whole key. It also partially reduces the compromise of one point of the infrastructure, because an isolated fragment cannot sign.
| Risk | Does MPC mitigate it? | What actually manages it |
|---|---|---|
| Theft of a single key | Yes, because the full key does not exist in one place | Cryptographic design and fragment distribution |
| Error or bad faith of one person | Yes, because no individual sees the full key | Internal processes of the custodian and the provider |
| Provider insolvency or mismanagement | No | Legal segregation, licences, contract and due diligence |
| Regulatory change or sanction on the provider | No | Regulatory monitoring and the company's exit plan |
| Stablecoin issuer failure or loss of peg | No | Issuer and reserve analysis, diversification |
| Improper approval of a payment inside the company | No | The company's own policies and controls |
The honest reading of Table 1 is that MPC strengthens the security of the key, not the solvency of whoever holds it. A company can be well protected against theft and still exposed to provider insolvency. That is why custody technology is assessed alongside the counterparty framework, not instead of it.
Issuer risk deserves its own note. USDC and USDT are stablecoins issued by different private entities, and their value depends on each issuer's reserves and management. No custody, however sophisticated, protects against a loss of peg. We look at this in USDC versus USDT for companies.
The signing engine: what happens when your company pays payroll or converts balance
The custodian's signing engine is the component every balance movement passes through, whether a payroll run, a withdrawal or a conversion. Soulbit prepares the operation, the custodian signs it with the MPC fragments cooperating, and the transaction is published to the network. No movement skips that step.
A hypothetical case: a Peruvian engineering consultancy with around 45 staff uploads a batch payroll file. The platform validates the file, the custodian signs each payment and recipients receive the balance. That signature is where cryptography replaces the single key of a traditional setup.
Two controls accompany the movement. The first is on-chain transaction monitoring, known as KYT, which looks for risky patterns and counterparties; we explain it in KYT and AML: payment monitoring. The second is verifying the company before it operates, KYB, described in what KYB is.
MPC signing protects the key, KYT watches transactions and KYB identifies who operates the account. No layer replaces the others.
Institutional custody and counterparty risk: what you depend on the provider for
With institutional custody, the company depends on the provider to access its balance, and that dependence is counterparty risk even when the signing technology is strong. Accepting it is part of the deal; ignoring it is the mistake. The useful question is how much risk the company takes and what evidence supports it.
Regulators take this seriously. Regulation (EU) 2023/1114, known as MiCA, governs in Article 75 the safekeeping and administration of crypto-assets on behalf of clients. Among other things it requires a custody policy and the separation of clients' holdings from the provider's own, and it makes the provider liable for loss of crypto-assets or of the means of access where the loss is attributable to it.
The Basel Committee published its standard Prudential treatment of cryptoasset exposures in December 2022. It is aimed at banks and includes operational risk among the risks to be managed.
What should a CFO obtain in writing before leaving a balance on a custodial platform?
A CFO should obtain in writing the identity of the entity that holds the keys, the legal mechanism that segregates client funds, the liability regime for a loss and the available third-party reports, with their scope and date. These answers should not be assumed, and no serious provider should refuse to document them.
| Due diligence question | What the provider should answer | Supporting document |
|---|---|---|
| Who holds the keys? | The entity that manages them and its contractual relationship with the provider | Written description of the custody model |
| How are client funds segregated? | The legal mechanism separating the client's balance from the provider's own | Contract or terms of service |
| Who is liable if there is a loss? | The liability regime and its limits | Service contract clauses |
| Is there insurance cover on the funds? | If so, scope, limits and exclusions; if not, a statement that none exists | Policy or written declaration |
| Which third-party reports exist? | Audits or attestations with their scope and date | Most recent report |
| What withdrawal time applies under stress? | Operating times and conditions for suspension | Contract and operating policy |
This article does not assert answers to every row of Table 2 for Soulbit. That is why the table is written as a questionnaire for any provider, not as a Soulbit fact sheet. Apply it to Soulbit too before operating, and ask for each answer in writing.
How three companies in different countries read it
The same custody model reads differently by country, because the regulator, the accounting and banking habits change. The three cases below are hypothetical and meant to illustrate questions, not to describe real clients.
A Peruvian mining-services supplier with 30 staff wants to hold a USDC balance between collecting from a foreign customer and paying subcontractors. Its CFO asks what authorisation the provider relies on and how fund origin is documented.
An Ecuadorian flower exporter wants to collect in dollars and pay growers. Its accountant asks what custody evidence can be filed at month end and who is liable if a balance is blocked.
A Brazilian software house billing European clients studies MiCA, because its customers' provider operates under it. Its lawyer wants to confirm whether declared compatibility equals authorisation, a distinction we explain in MiCA 2026 for Latin American companies.
In all three cases the MPC technology is the same. What changes is the counterparty question. Institutional custody answers well the question of key theft and leaves open who answers to the company.
What Soulbit V1 delivers in custody and what it does not
Soulbit V1 provides institutional custody with MPC: an institutional custodian manages the wallet keys, not the client, and every movement passes through that custodian's signing engine. It also includes on-chain transaction monitoring and KYB verification of companies. That is what we can state today.
What this article does not state matters equally. We do not say client-configurable approval rules exist, nor insurance on funds, nor a guarantee of repayment, nor that balances have the protection of a deposit guarantee scheme. Soulbit holds no banking licence. We make no claims on certifications, audits or yield on balances.
Mobile apps and the card are not yet available. MiCA compatibility is a design intention, not a licence. For any Table 2 question not yet publicly answered, the advice is the usual one: ask directly and require a written answer before operating.
When is a custodial model not a good fit?
When a company needs to control the keys to its assets itself, by internal policy or applicable regulation, a custodial service does not fit, and it is better to say so plainly. The custodial model suits those who prefer not to run key infrastructure and accept a counterparty risk that has been assessed and documented.
Frequently asked questions
What is institutional custody of digital assets?
Institutional custody is a service in which a specialised entity holds and protects the private keys that control a client's digital assets. The client company does not manage those keys. It relies on the custodian to protect them and to sign every movement, which brings operational convenience and dependence on the provider.
What does MPC mean in crypto custody?
MPC stands for multi-party computation. The key is generated and used in fragments held in different places, and to sign a transaction the fragments cooperate without ever assembling a complete key. Compromising a single fragment is therefore not enough to move the funds.
Does MPC custody remove the risk of losing the balance?
No. MPC reduces the risk that a single key is stolen or misused, but it does not remove the risk of the custodial entity, regulatory risk or the risk of the stablecoin issuer. A company that leaves its balance with a custodial provider still carries counterparty risk and should assess it separately.
What should a CFO ask a custody provider before leaving a balance?
A CFO should ask which entity holds the keys, how client funds are legally segregated, who is liable for a loss and which third-party reports exist, with their scope and date. It is also worth asking what approval controls the service supports and what withdrawal times apply under stress. Every answer should be in writing.
Can a Peruvian, Chilean or Brazilian company use institutional custody with MPC?
Yes, provided its use of digital assets is compatible with local rules and with the company's own policies. Each jurisdiction treats digital-asset providers differently, so the company should confirm with its legal adviser which authorisation the provider relies on. This article is informational and does not replace that review.
Want your company to add stablecoins to its operations?
Join the Soulbit waitlist and start paying payroll, collecting and managing treasury without SWIFT.
Join the waitlist