Blockwyse.
For regulated institutions

Built to pass a third-party risk review

Our clients include regulated financial institutions and authorised crypto-asset service providers. Being able to survive their procurement, outsourcing and resilience requirements is not an overhead for us. It is the product.

Why this page exists

Most crypto software vendors have never been through a bank's onboarding, and it shows the moment a third-party risk questionnaire arrives. Engagements stall for months on contract terms that were never drafted with an ICT service provider in mind.

We start from the other end. Our contracting, documentation and delivery model is built around what a supervised institution has to be able to demonstrate about the people it buys technology from.

Outsourcing governance

Supporting the governance you owe your supervisor

Retained control, evidenced
Your supervisor holds you responsible for what you outsource. We work so that responsibility stays visibly yours: documented decision rights, your governance forums, your sign-offs, and artefacts your second line can put in front of a competent authority.
No letter-box structures
Supervisors resist arrangements where a licensed entity has outsourced away its substance. We scope engagements so the reserved activity, and the capability to supervise it, stay inside your perimeter.
Register of information support
We supply the contractual and technical detail your register entries require, in the format your operational resilience function actually has to file.
Subcontracting transparency
A current picture of any subcontractors, what they do, where they do it, and what changes without your consent. Which is nothing material.
ICT contracting

We contract on terms designed for DORA

Supplying technology to a CASP, bank or investment firm makes us an ICT third-party service provider. The contractual minimum is prescribed, and we treat it as a starting point rather than a negotiation.

Full service description
What is provided, by whom, and with what boundaries, not a marketing summary.
Locations of provision and data processing
Named, current, and notified before they change.
Availability, integrity and confidentiality
Explicit provisions for the protection of your data, including in transit and at rest.
Data access, recovery and return
Your data comes back in a usable form on termination or insolvency, with the process agreed in advance rather than negotiated in a crisis.
Service levels and reporting
Quantitative targets, measured and reported, with defined consequences.
Incident assistance
Support during ICT incidents at no additional cost, or at a cost agreed up front, not a change request raised while you are in an outage.
Cooperation with authorities
We cooperate with your competent and resolution authorities, including access and inspection rights.
Termination and notice
Defined rights and notice periods on both sides, with an exit plan already written.
Security awareness participation
Our people take part in your ICT security awareness and training programmes.
The boundary

The clearest thing we can tell a risk committee is what we never do

What we do

  • Design, build, integrate and support the systems you operate
  • Analyse markets, protocols, flows and counterparty risk
  • Produce the evaluation frameworks and technical due diligence behind your own decisions
  • Contract on terms your third-party risk function can actually approve
  • Work alongside your legal advisers, giving them the technology detail they need
  • Hand over documentation, runbooks and an exit path from the first week

What we never do

  • Hold your crypto-assets, your private keys, or any other means of access to them
  • Receive, hold or transmit orders for anyone
  • Operate a system that brings together third-party buying and selling interests
  • Exercise discretion over anyone's assets
  • Face your clients, or appear to them as the provider of your service
  • Take a referral fee, rebate or introduction commission from any provider
Security and assurance

Posture

SOC 2 Type II (in preparation)
Control design work is underway. We will publish the report status rather than imply a certification we do not yet hold.
Secure development
Code review, dependency and secret scanning, environment separation, least-privilege access, and change records you can audit.
No access to key material
We design custody and key management architecture. We do not hold key material, and our systems are built so that we cannot.
Audit and access rights
Contractual access for you, your auditors and your competent authorities, with a defined process rather than an ad-hoc one.
Exit planning
Written at the start of the engagement, not the end: data return format, knowledge transfer, code and documentation handover, and a realistic timetable.
Data protection
GDPR-aligned processing terms, named locations, and sub-processor transparency.

Send us your questionnaire.

If your third-party risk team has a pack, send it. We would rather answer it early than discover a blocker at contract stage.