Resources · Compliance

Built to be examined.

Our regulatory posture, AML program, and audit trail — written the way a diligence team reads them. Everything on this page is available in document form under NDA.

Regulatory posture

holdway is organized to operate within a qualified-custodian framework. We will describe that plainly, because a young custodian that overstates its charter is a custodian you should not use.

Today, holdway operates under money-services registration, with a trust-company charter application in progress. Until the charter is granted, we do not call ourselves a trust company, and our client agreements do not depend on us being one. What clients rely on now is structural and contractual, not aspirational:

  • Segregation by design. Every client's assets sit in per-client segregated wallets, on-chain and in our books. There is no omnibus pool to unwind. See how custody works.
  • Bankruptcy-remote by contract. Our custody agreement states that client assets remain client property at all times, are held for the client's benefit, and do not form part of holdway's estate. Assets are never lent, staked, pledged, or rehypothecated. If holdway fails, the agreement and the on-chain segregation are what a receiver works from — and both point the same direction: the assets go back to you.
  • Verification, not trust. Independent on-chain proof-of-reserves attestation lets clients confirm segregation without asking us. See Reporting.
When our charter status changes, we will update this page, notify clients in writing, and re-paper agreements where the change is favorable to clients. We will not announce a license before it exists.

AML & KYC program

A written AML program sits under a named officer who owns it, is independently tested every year, and drives role-specific training across the firm. Because our clients are institutions, the program is built around entities rather than retail identity checks.

Client onboarding

Every prospective client goes through documented onboarding before an account is funded: entity formation and good-standing verification, identification of beneficial owners at the 25% threshold (lower where risk warrants), identification of control persons, and source-of-funds review proportionate to expected activity. Enhanced due diligence applies to clients in higher-risk jurisdictions or with complex ownership chains.

Sanctions and address screening

We screen the entity, its beneficial owners, and its authorized users against OFAC and equivalent international sanctions lists at onboarding and continuously thereafter. On-chain, we screen counterparty addresses and withdrawal destinations against sanctions designations and known-illicit clusters before a transfer executes. A screening hit stops the transfer and routes it to compliance review; it does not silently proceed.

Travel rule

For transfers to and from virtual-asset service providers, we collect and transmit required originator and beneficiary information in line with travel-rule obligations. Withdrawal allow-lists — described under Security — make this tractable: destinations are known and attested before the first transfer, not discovered after it.

Audits & attestations

Three independent examinations recur on a fixed calendar:

  • SOC 2 Type II — renewed annually, covering security, availability, and confidentiality controls over the full audit period, not a point-in-time snapshot.
  • Penetration testing — independent testers engage the platform, the API, and the key-management boundary at least annually and after material architecture changes. Findings are tracked to remediation.
  • Proof of reserves — an independent attestation that on-chain holdings match client liabilities, wallet by wallet. Clients can verify the underlying addresses themselves; the method is documented under Reporting.

Current reports are available to clients and qualified prospects under NDA. We do not publish redacted marketing summaries in their place.

The due-diligence pack

Most institutional reviews ask for the same body of evidence, so we keep it assembled. The current pack contains:

  • The most recent SOC 2 Type II report, with bridge letter if the audit period has lapsed
  • Insurance certificates and a summary of coverage terms — see Insurance for what the policy actually covers
  • A policy-control matrix mapping our written policies to implemented controls and audit evidence
  • Organizational and key-ceremony documentation: who holds which roles, how MPC key shards are generated and distributed, and the quorum required to act
  • The current subprocessor list with categories and jurisdictions

To request it, write to compliance@holdway.xyz from your institutional domain. We turn around NDA execution and pack delivery within five business days, and we will sit our compliance officer across from yours if the documents raise questions.

Subprocessors

We keep the subprocessor surface deliberately small. By category:

  • Cloud infrastructure — hosting for the platform and API. No subprocessor in this category can access private key material.
  • HSM and facility providers — hardware security modules and the physical sites where cold-storage key shards reside.
  • Screening data — sanctions-list and blockchain-analytics data feeding the checks described above.

Each subprocessor is vetted before engagement and re-vetted annually against our security and confidentiality requirements. Clients receive 30 days' written notice before a new subprocessor handles client data, with the right to object. The named list is part of the due-diligence pack.

Regulator & law-enforcement requests

When we receive a request from a regulator or law-enforcement agency, the process is the same every time: counsel reviews the request for legal validity, we narrow it to what the instrument actually compels, and we produce only that. We challenge requests that are defective or overbroad.

We notify the affected client before or promptly after disclosure unless a court order or statute prohibits it — and where a non-disclosure order has a term, we notify the client when it expires. Our client agreement, in Legal, reflects the same commitment. A regulator can compel information about your account; it cannot quietly move your assets, because withdrawals still require your quorum.

Send us your diligence questionnaire.