Built to pass a third-party risk review
Our clients include regulated financial institutions and authorised crypto-asset service providers. Being able to survive their procurement, outsourcing and resilience requirements is not an overhead for us. It is the product.
Most crypto software vendors have never been through a bank's onboarding, and it shows the moment a third-party risk questionnaire arrives. Engagements stall for months on contract terms that were never drafted with an ICT service provider in mind.
We start from the other end. Our contracting, documentation and delivery model is built around what a supervised institution has to be able to demonstrate about the people it buys technology from.
Supporting the governance you owe your supervisor
- Retained control, evidenced
- Your supervisor holds you responsible for what you outsource. We work so that responsibility stays visibly yours: documented decision rights, your governance forums, your sign-offs, and artefacts your second line can put in front of a competent authority.
- No letter-box structures
- Supervisors resist arrangements where a licensed entity has outsourced away its substance. We scope engagements so the reserved activity, and the capability to supervise it, stay inside your perimeter.
- Register of information support
- We supply the contractual and technical detail your register entries require, in the format your operational resilience function actually has to file.
- Subcontracting transparency
- A current picture of any subcontractors, what they do, where they do it, and what changes without your consent. Which is nothing material.
We contract on terms designed for DORA
Supplying technology to a CASP, bank or investment firm makes us an ICT third-party service provider. The contractual minimum is prescribed, and we treat it as a starting point rather than a negotiation.
- Full service description
- What is provided, by whom, and with what boundaries, not a marketing summary.
- Locations of provision and data processing
- Named, current, and notified before they change.
- Availability, integrity and confidentiality
- Explicit provisions for the protection of your data, including in transit and at rest.
- Data access, recovery and return
- Your data comes back in a usable form on termination or insolvency, with the process agreed in advance rather than negotiated in a crisis.
- Service levels and reporting
- Quantitative targets, measured and reported, with defined consequences.
- Incident assistance
- Support during ICT incidents at no additional cost, or at a cost agreed up front, not a change request raised while you are in an outage.
- Cooperation with authorities
- We cooperate with your competent and resolution authorities, including access and inspection rights.
- Termination and notice
- Defined rights and notice periods on both sides, with an exit plan already written.
- Security awareness participation
- Our people take part in your ICT security awareness and training programmes.
The clearest thing we can tell a risk committee is what we never do
What we do
- Design, build, integrate and support the systems you operate
- Analyse markets, protocols, flows and counterparty risk
- Produce the evaluation frameworks and technical due diligence behind your own decisions
- Contract on terms your third-party risk function can actually approve
- Work alongside your legal advisers, giving them the technology detail they need
- Hand over documentation, runbooks and an exit path from the first week
What we never do
- Hold your crypto-assets, your private keys, or any other means of access to them
- Receive, hold or transmit orders for anyone
- Operate a system that brings together third-party buying and selling interests
- Exercise discretion over anyone's assets
- Face your clients, or appear to them as the provider of your service
- Take a referral fee, rebate or introduction commission from any provider
Posture
- SOC 2 Type II (in preparation)
- Control design work is underway. We will publish the report status rather than imply a certification we do not yet hold.
- Secure development
- Code review, dependency and secret scanning, environment separation, least-privilege access, and change records you can audit.
- No access to key material
- We design custody and key management architecture. We do not hold key material, and our systems are built so that we cannot.
- Audit and access rights
- Contractual access for you, your auditors and your competent authorities, with a defined process rather than an ad-hoc one.
- Exit planning
- Written at the start of the engagement, not the end: data return format, knowledge transfer, code and documentation handover, and a realistic timetable.
- Data protection
- GDPR-aligned processing terms, named locations, and sub-processor transparency.
Send us your questionnaire.
If your third-party risk team has a pack, send it. We would rather answer it early than discover a blocker at contract stage.