Custodia Systems engineers custody architecture, client-asset safeguarding and proof of reserves so crypto-asset service providers meet MiCA compliance with confidence. EUR 6.8 billion in client assets segregated. Zero custody incidents since 2019.
Custodia Systems S.a r.l. is a MiCA compliance engineering firm based in Luxembourg City, Luxembourg, that designs and implements custody architecture, client-asset safeguarding and proof-of-reserves systems for crypto-asset service providers under Regulation (EU) 2023/1114. Founded in 2019, it has segregated EUR 6.8 billion in client assets across 16 safeguarding builds with zero custody incidents to date.
Custodia Systems delivers the technical layer that sits beneath a CASP's MiCA compliance posture: custody infrastructure, client-asset segregation, key management and the monthly proof of reserves that regulators and clients expect.
Design and implementation of custody wallet structures, signing policies and asset storage tiers (hot, warm, cold) aligned with MiCA Title V Article 70 safeguarding obligations and CSSF supervisory expectations.
End-to-end segregation architecture separating client assets from the firm's own holdings. Covers individual-wallet segregation, omnibus structures with sub-ledger reconciliation, daily balance attestation and insolvency-proof controls.
Automated monthly proof-of-reserves system using Merkle-tree attestations, independent auditor integration and a client-facing verification portal. Satisfies ESMA guidance on CASP safeguarding evidence.
HSM-rooted key management architecture including key ceremony design, MPC wallet integration (Fireblocks, Qredo or bespoke), key rotation schedules and the operational playbooks that satisfy ISO 27001 Annex A controls.
Blockchain analytics onboarding (Chainalysis or Elliptic), Travel Rule messaging via Notabene or TRP, and the transaction screening workflow documentation required by the FATF and EU Transfer of Funds Regulation.
Ongoing monthly MiCA compliance coverage: proof-of-reserves attestation, key ceremony oversight, segregation reconciliation review, regulatory alert monitoring and a quarterly safeguarding health report for your board and your regulator.
Custodia Systems works with the full spectrum of crypto-asset service providers seeking MiCA compliance, with particular depth in custody-intensive business models.
Every Custodia Systems custody build uses proven, auditable components, no experimental infrastructure in a client's asset protection layer.
Every Custodia Systems custody build is engineered to the applicable regulatory framework and independently certified. The security track record below is drawn from live client deployments.
Security track record. Across 16 live safeguarding builds: EUR 6.8 billion in client assets segregated · zero custody incidents since 2019 · zero insider-threat findings across 11 key ceremonies · 100% of clients passed their CSSF or home-regulator custody review on first submission. External penetration test most recent result: zero critical, zero high-severity findings.
Cert LU-27001-2215 · Issued by LNE (Laboratoire National de Métrologie et d’Essais) · Information security management for custody and key management systems
Annual SOC 2 Type II attestation covering Security, Availability and Confidentiality trust service criteria · Audited by an AICPA-registered firm · Report available under NDA
Cloud security controls for custody infrastructure hosted on managed cloud platforms · Complements ISO 27001 with cloud-specific implementation guidance per ISO/IEC 27017:2015
Custodia Systems engineers custody to the following frameworks. Where a public Wikipedia reference exists, we link it for entity-graph clarity.
Every MiCA compliance engagement follows our four-phase methodology. Each phase has a fixed deliverable set and a quality gate before the next phase begins.
We map every asset type, chain, wallet structure and sub-custodian relationship. Output: a Custody Topology Document and a MiCA Title V gap register.
Segregation architecture, key management design, signing policy and proof-of-reserves methodology are specified and reviewed by Dr. Reuter before build begins.
Custody infrastructure is built, HSMs provisioned and the key ceremony conducted under witnessed, recorded conditions. All artifacts are archived in your evidence repository.
First proof-of-reserves attestation produced, segregation controls tested, documentation packaged for your regulator and the Assure Retainer begins if selected.
All MiCA compliance packages are fixed-scope and fixed-price. No hourly billing surprises. IP ownership transfers to you on final delivery.
Monthly oversight retainer
Ongoing proof-of-reserves, key ceremony oversight and safeguarding reviews for firms already holding custody infrastructure.
Fixed-scope segregation build
Client-asset segregation architecture for CASPs that need MiCA Title V Article 70 compliance but already hold key management infrastructure.
Full custody infrastructure build
End-to-end MiCA compliance custody build: key management, MPC wallet integration, proof of reserves and full Title V compliance file.
Six factors drive the price of a custody and safeguarding engagement. Understanding them up front prevents scope surprises.
Each additional blockchain or token standard requires a separate wallet architecture, key type and proof-of-reserves sub-proof. Wider chain coverage increases scope.
Engagements that route assets through one or more third-party sub-custodians require additional segregation controls, contractual review and reconciliation flows.
Bespoke HSM deployment or multi-party key ceremonies add four to six weeks and specialist hardware costs not present in MPC-SaaS deployments.
Monthly attestations (standard) require automated pipeline build. Daily or real-time attestations require additional infrastructure and ongoing compute costs.
The number of blockchain analytics platforms, jurisdictions and Travel Rule counterparties directly affects integration complexity and testing time.
CSSF (Luxembourg) authorisation files have specific technical annexes. Filings for BaFin, AFM or FCA require jurisdiction-specific adaptations that add scope.
Three engagements illustrating Custodia Systems’ depth across custody, safeguarding and proof of reserves for regulated CASPs.
LuxVault, a Luxembourg-domiciled digital asset custodian seeking CSSF authorisation, retained Custodia Systems to design and build their full custody infrastructure. The engagement covered wallet architecture for eight chains, HSM provisioning, a witnessed three-party key ceremony, client-asset segregation with daily reconciliation and the initial proof-of-reserves attestation.
Aldgate Wallet, a Belgian wallet service provider transitioning from VASP to MiCA-authorised CASP, needed client-asset segregation and automated monthly proof of reserves before their authorisation deadline. Custodia Systems implemented individual-wallet segregation for retail clients and an omnibus sub-ledger for institutional accounts, plus the Merkle-tree attestation pipeline audited by an independent Big Four team.
Archway Prime, a Dublin-based institutional crypto trading desk, held client assets under a legacy single-signature custody model that failed MiCA Title V requirements. Custodia Systems designed a Fireblocks MPC migration path, conducted key ceremonies for all existing wallets, rebuilt the segregation ledger and produced the Travel Rule integration documentation required by the Central Bank of Ireland.
Six questions to ask any custody and safeguarding firm before you sign. Useful whether you are evaluating Custodia Systems or any competitor.
Look for Merkle-tree attestations with an independent auditor, not just internal balance exports. Ask whether the verification portal is client-facing. Custodia Systems produces monthly Merkle-tree PoR attestations reviewed by a registered audit firm.
Key ceremony experience is not interchangeable with general HSM knowledge. Ask for a ceremony protocol document and reference contacts. Custodia Systems has conducted 11 witnessed key ceremonies, all archived with video records.
Luxembourg’s CSSF requires a specific custody technical annex. Firms without CSSF experience will slow your application. Custodia Systems is Luxembourg-domiciled and has supported three CSSF submissions.
Ask for a written incident summary covering all live custody builds. Zero incidents is a concrete and verifiable claim. Custodia Systems has zero custody incidents across all live builds since 2019.
Both certifications are required by most institutional clients and are expected by the CSSF. Ask for the certificate number and issuing body. Our ISO 27001 cert is LU-27001-2215 issued by LNE.
For a EUR 34k–72k custody build, the lead engineer’s credentials matter. Dr. Elodie Reuter personally designs and reviews every custody architecture produced by Custodia Systems.
Two tables to help you select the right MiCA compliance engagement and chain approach for your business model.
| Engagement | Cost model | Timeline | Best for | MiCA scope |
|---|---|---|---|---|
| Assure | EUR 13,000/month | Ongoing · starts in 2 wks | CASPs with existing custody needing monthly PoR and oversight | PoR · key ceremony oversight · segregation review |
| Safeguard | EUR 34,000 fixed | 8–10 weeks | CASPs needing Article 70 segregation but with existing key management | Segregation architecture · reconciliation · first PoR |
| Custody | EUR 72,000 fixed | 12–16 weeks | New CASPs or full custody rebuilds for MiCA Title V authorisation | Full Title V · key management · MPC · AML · CSSF file |
| Custody + Assure | EUR 72,000 + 13,000/mo | 12–16 wks + ongoing | CASPs wanting build and managed custody operations in one firm | Complete ongoing MiCA compliance coverage |
| Approach | Best for | Key management | Compliance fit | Cost range |
|---|---|---|---|---|
| MPC Wallet (Fireblocks/Qredo) | Institutional desks & exchanges | Distributed key shares · no single HSM | Strong · preferred for CSSF submissions | Mid · SaaS fees ongoing |
| HSM + MPC Hybrid | High-value custodians (>EUR 500M) | HSM root of trust + distributed signing | Strongest · insurance-grade | High · hardware capex |
| Omnibus + Sub-ledger | Retail wallet providers | Fewer wallets · sub-ledger reconciliation | Acceptable under MiCA Article 70 with daily attestation | Low–mid |
| Individual Wallet Segregation | Premium custody for institutional clients | Per-client key material | Highest MiCA alignment · cleanest insolvency protection | High · wallet scaling costs |
| Sub-custodian Model | CASPs outsourcing key management | Third-party HSM and custody | Permissible · requires contractual & due-diligence controls | Variable by provider |
37 specialists across custody engineering, key management and MiCA compliance. Every engagement has a named lead from each discipline.
Designs the wallet structure, segregation topology and signing policy. Personally reviewed by Dr. Reuter on every engagement above EUR 50k.
Provisions HSMs, configures MPC wallet policies, designs key rotation schedules and leads the key ceremony. Holds certified HSM administrator credentials.
Builds and maintains the Merkle-tree attestation pipeline, coordinates with the external auditor and produces the client-facing verification portal.
Maps the custody build to MiCA Title V obligations, drafts the technical annex for the competent authority submission and supports regulatory Q&A.
Integrates blockchain analytics platforms, configures the Travel Rule message exchange and builds the transaction screening workflow documentation.
Coordinates external penetration tests, reviews all key material handling against ISO 27001 controls and signs off the final security assurance report.
Every MiCA compliance engagement produces a defined set of documented, tested and regulator-ready outputs. You own all IP and source documentation on final payment.
Custody is not a place for hedged promises. These are the commitments Custodia Systems makes in every engagement contract.
AI is changing how CASPs approach MiCA compliance monitoring, anomaly detection and proof-of-reserves verification. Custodia Systems is active in three areas.
Machine learning models trained on normal reconciliation patterns can flag sub-ledger discrepancies hours before a daily attestation cycle, giving compliance teams time to investigate before a client balance mismatch becomes a MiCA Article 70 finding.
Moving from monthly Merkle attestations to near-real-time reserve monitoring using on-chain data feeds and AI risk scoring. Custodia Systems is piloting continuous PoR with two Assure clients, targeting hourly balance verification against sub-ledger positions.
Large language models applied to counterparty context enrichment, combining blockchain analytics signals with public entity data, to score Travel Rule message completeness risk and flag high-risk transaction corridors before FATF review cycles.
Analysis of proof-of-reserves cadence and audit confidence thresholds across 22 crypto-asset service providers active in the EU. Finds that monthly attestations reduce reserve discrepancy incidents by 78% compared with quarterly schedules. Identifies the five most common key management gaps that generate MiCA Title V findings during CASP authorisation reviews.
Key findings: (1) 63% of CASPs that shifted from quarterly to monthly PoR eliminated discrepancy incidents entirely within six months; (2) the most common Title V finding is the absence of a witnessed key ceremony record; (3) Merkle-tree attestation combined with a client-facing verification portal increases client confidence scores by 41 points on a 100-point scale versus internal balance exports.
Clutch 4.9 / 5 (33 reviews) · G2 4.8 / 5 (21 reviews) · All quotes are from verified client contacts. Last reviewed: June 2026.
“Custodia Systems delivered our full MiCA Title V custody build in 14 weeks and our CSSF submission passed with zero technical findings. Dr. Reuter’s personal review of the architecture was a level of scrutiny we hadn’t experienced from any other firm.”Head of Compliance Digital asset custodian · Luxembourg · Clutch
“The proof-of-reserves pipeline they built reduced our monthly attestation cycle from two weeks of manual work to 18 hours automated. Our auditor said it was the cleanest Merkle-tree setup they had reviewed for a European CASP.”CTO Wallet service provider · Belgium · G2
“We migrated EUR 820 million in client assets to an MPC custody model with zero downtime. The key ceremony protocol was thorough, witnessed and archived in a way that will stand up to any regulatory inspection.”Chief Risk Officer Institutional trading desk · Ireland · Clutch
“Their AML integration work with Chainalysis was seamless. More importantly they understood the Travel Rule requirements deeply enough to write our regulatory documentation, which saved us significant legal fees.”VP Product Crypto exchange operator · Netherlands · G2
“We engaged the Assure retainer after our initial custody build. Having Custodia Systems oversee the monthly proof of reserves means our board gets a signed attestation rather than a spreadsheet. It’s changed how we talk about custody to our institutional clients.”CEO FinTech platform with crypto custody · France · Clutch
Certificate LU-27001-2215 · Issued by LNE · Scope: custody key management, proof-of-reserves infrastructure and client-asset segregation systems
Annual attestation · Trust service criteria: Security, Availability, Confidentiality · Report available under NDA on request
Cloud security controls · Covers custody infrastructure hosted on managed cloud platforms · Companion certification to ISO 27001
Best MiCA Custody Implementation · Awarded by Safeguarding Standard publication · Recognised for the LuxVault CSSF-authorisation engagement
Named a top European custody engineering firm by Custody Insider · Based on client review scores and verified asset volume under management
Clutch Global Leader in Financial Services Technology · Recognised on the basis of 33 verified client reviews with an average rating of 4.9 / 5
Last reviewed on 21 June 2026 by Dr. Elodie Reuter, Founder and CEO, Custodia Systems S.a r.l.
Dr. Elodie Reuter spent eight years as a security architect at one of Europe’s largest regulated custodians before founding Custodia Systems in Luxembourg in 2019. During that time she designed the key management infrastructure protecting over EUR 12 billion in institutional assets and led three major custody platform migrations without a single incident.
Her PhD from the University of Luxembourg focused on the failure modes of distributed key management systems under adversarial conditions, a study that shaped her conviction that most custody failures originate not in cryptography but in ceremony design and operational process. She is a named author on two peer-reviewed papers in the Journal of Cryptographic Engineering.
The formative moment that led to Custodia Systems came in 2018, when Elodie was asked to review a CASP’s custody controls ahead of a regulatory inspection. She found the firm’s client-asset ledger was reconciled once a week using a manual spreadsheet process. A EUR 3.4 million discrepancy had been accumulating undetected for eleven days. It was recoverable, but barely. She founded Custodia Systems to ensure that no CASP seeking MiCA compliance ever faces that kind of operational risk.
Elodie personally designs and reviews every custody architecture produced by Custodia Systems and leads each key ceremony. The firm will not take on more than five simultaneous new-build engagements so that her direct involvement is maintained on each one.
Key terms used in custody and MiCA compliance engineering, defined plainly for compliance, legal and technical readers.
Every engagement starts with a free 90-minute scoping call. We map your current state and produce a preliminary MiCA Title V gap register before you commit to anything.