Platform · Insurance

Insurance is the last layer. Not the first.

A policy document has never stopped a theft. Ours exists for the failure modes the architecture cannot rule out — and this page says plainly what it covers, how a claim would work, and what it does not cover.

Where insurance sits

Coverage backs the architecture. It does not replace it.

Some custodians lead with an insurance figure and hope you stop reading there. We think that order is backwards. The first line of defense is the control system described on Security: MPC key management with no complete key anywhere, geographically separated shards, and a policy engine that evaluates every withdrawal before anything signs.

Insurance is what stands behind that system for the residual risk — the scenarios that are engineered to be improbable but cannot be engineered to be impossible. An underwriter's actuaries examined our architecture, our facilities, and our operating procedures before putting capital at risk on them. That examination is itself a form of assurance: coverage at institutional terms is only written against controls that survive scrutiny.

Read the two pages together. Security explains why a loss is unlikely. This page explains what happens if one occurs anyway.

Coverage structure

Two policies, matched to the two tiers of custody.

Assets at holdway live in two tiers — deep cold storage for reserves, a warm tier for operational balances — and the insurance program mirrors that split, because the risks are different.

Specie coverage applies to assets whose key material sits in deep cold storage. Specie is the class of insurance built for vaulted valuables, and it treats key shards the way it treats bullion: it responds to physical loss, physical destruction, and theft of the key material held in our hardened facilities.

Crime coverage applies to the warm and operational systems — the tier that is, by design, closer to the network. It responds to theft by external attack and to internal collusion: the scenario where insiders conspire to defeat the dual controls described on Security.

Both policies are placed with underwriters at established specie and crime markets, and both are renewed annually against the current asset profile.

holdway · insurance program
Specie policy
Deep cold storage · key material in vaulted facilities
In force
Covers
Theft · physical loss · destruction of key material
Cold tier
Crime policy
Warm & operational systems
In force
Covers
External theft · internal collusion
Warm tier
Renewal
Annual · re-underwritten against current custody profile
Reviewed yearly

Segregation and claims

Your claim maps to your assets. Not to a pool.

Insurance on an omnibus custodian has an ugly failure mode: after a loss, every client holds a pro-rata claim on a pooled pot, and the recovery depends on how everyone else's assets fared.

holdway does not pool. Every client's assets sit in bankruptcy-remote, per-client segregated wallets — the structure described on Custody — so a loss event is attributable on-chain to specific wallets belonging to a specific client. A claim therefore concerns identifiable client assets with an identifiable on-chain history, not a share of a commingled balance.

That precision cuts both ways, and we consider both directions a feature: clients unaffected by an incident are not dragged into someone else's claim, and affected clients do not have their recovery diluted by unaffected balances.

  • Per-client wallets — losses attach to named, segregated accounts, never a house pool
  • On-chain attribution — the affected assets, amounts, and movements are provable from the chain itself
  • Clean quantification — proof of reserves attestations before and after the event bound the loss precisely
  • No cross-client dilution — one client's incident is not every client's problem

Exclusions

What is not covered. Stated plainly.

Every insurance program has exclusions. Most custody marketing hopes you will not ask about them. Here are ours, in ordinary language:

Not covered: market and price movements — insurance is not a hedge, and a fall in the value of ETH, BTC, or any other asset is not a loss event. On-chain protocol failures — a bug, exploit, or consensus failure in an underlying blockchain or token contract is outside the program. Losses caused by a client's own compromised credentials or by instructions the client's approvers duly approved — if your quorum authorizes a transfer to an attacker's allow-listed address, the policy engine did its job and the coverage does not respond.

That last exclusion is why we push clients toward tighter policies — higher quorums, longer time-locks, conservative velocity limits. The controls you configure on Security are the coverage for the risks insurance will not take.

  • Market moves — excluded; price risk belongs to the owner of the asset
  • Protocol failures — excluded; we custody keys, we do not underwrite blockchains
  • Client-side compromise — excluded; your credentials and your approvals are your perimeter
  • Duly approved instructions — excluded; an authorized transfer is a transfer, even a regretted one

The claims process

If the worst happens, here is the sequence.

Notification. On discovery of a loss event we notify affected clients and the underwriters, in parallel, and open a claim file. Clients are not left to find out at renewal time.

Evidence. The claim is built from the immutable audit trail described on Reporting: every instruction, approval, policy evaluation, and signing event relevant to the loss, alongside the on-chain record of the affected segregated wallets. Because the trail is append-only and the wallets are per-client, assembling evidence is an export, not a reconstruction.

Adjustment. The underwriters' loss adjusters get supervised access to the same records, our facilities, and our personnel. Segregation keeps their scope narrow: they examine the affected client's wallets and the relevant control history, not the whole book.

Timeline. We commit to same-day notification of affected clients, a complete evidence package to adjusters within ten business days, and written status updates to affected clients at least every two weeks until the claim resolves.

  • Same-day notification — affected clients and underwriters informed in parallel
  • Evidence by export — append-only audit trail plus the on-chain record; nothing reconstructed after the fact
  • Scoped adjustment — adjusters see the affected wallets and controls, not every client's business
  • Standing updates — written status to affected clients at least every two weeks

Verifying our coverage

Ask for the certificates. We expect you to.

A paragraph on a website is not evidence of coverage, and a diligence team should not treat it as such. Certificates of insurance for both the specie and crime policies — naming the insured entity, the policy periods, and the coverage classes — are included in the due-diligence pack, alongside our SOC 2 Type II report and penetration-test summaries.

The pack is available under NDA through the process on Compliance. If your risk or legal team has questions the certificates do not answer, write to compliance@holdway.xyz and we will put them in front of the right people.

  • Certificates of insurance — specie and crime, current policy period, in the due-diligence pack
  • Under NDA — requested through Compliance, typically turned around in days
  • Re-verified annually — updated certificates issued to clients at each renewal

Architecture first. Insurance behind it. Evidence for both.