> For the complete documentation index, see [llms.txt](https://manual.mycactus.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://manual.mycactus.com/full-custody-solution/cactus-full-custody-solution.md).

# Cactus Full Custody Solution

## Overview

Cactus Full Custody provides institutional clients with a turnkey digital asset custody solution. All key management, infrastructure operations, and security are handled entirely by Cactus Custody, allowing institutions to focus on their core business. Assets are stored in enterprise-grade HSMs across geographically distributed data centres, with both warm and cold wallet storage available.

Full Custody is built on a segregated wallet architecture, with assets held in individually assigned wallet addresses under a three-level hierarchy of business line, wallet, and address. For a detailed breakdown, refer to [Cactus Custody Wallet Architecture](/introduction/cactus-custody-wallet-architecture.md).

***

## Why Full Custody

### Fully Managed Infrastructure

Cactus Custody manages all operational complexity from day one. There is no hardware to set up, no nodes to maintain, and no key management to handle. Enterprise-grade security and full platform functionality are available immediately upon onboarding.

### Zero Client-Side Dependency

Since Cactus Custody manages all signing infrastructure, there is no dependency on client-side systems for transaction processing. Operations continue uninterrupted regardless of your internal infrastructure status.

### Cold and Warm Storage

Configure the distribution of holdings between warm and cold storage based on your operational and security requirements. Cold wallet assets are stored in HSMs and kept fully offline, with transactions secured using multi-signature or TSS signing methods.

### Institutional Security Controls

Multi-level approval workflows, withdrawal whitelisting, withdrawal limits, role-based access control, and mobile approval tools ensure that every fund movement is governed by your organization's security policies. These controls are configurable at the business line level, allowing different security rules for different operations.

### Built-in Compliance

All deposits and withdrawals are subject to Chainalysis-powered [KYT transaction monitoring](/compliance-and-aml/kyt-transaction-monitoring.md). [Travel Rule](/compliance-and-aml/travel-rule.md) verification through Notabene is also available for clients.

### Insurance Coverage

USD 50 million in insurance coverage underwritten by OneDegree, protecting against risks such as theft, security breaches, and other qualifying loss events. For more details, please refer to [Cactus Custody Insurance Coverage](/insurance-coverage/cactus-custody-insurance-coverage.md).

***

## Private Key Management

All private keys are generated and stored within Cactus Custody's enterprise-grade HSM infrastructure. Full Custody clients delegate private key management entirely to Cactus Custody, removing the need to deploy or maintain any key infrastructure on your end.

For cold wallets, transaction signing is secured using one of two methods depending on the blockchain network and asset type: multi-signature or TSS (Threshold Signature Scheme). Both methods eliminate single-point-of-failure risk. To understand how each signing method works, refer to the cold wallet section in [Cactus Custody Wallet Architecture](/introduction/cactus-custody-wallet-architecture.md#cold-wallet).

***

## User Account & Security

This includes support for multiple administrators, role-based permissions, operator management, and account security controls. The [User Account & Security](/user-account-and-security/roles-and-permissions.md) section covers each of these topics in detail.

***

## Fund Security & Management

This includes the policy engine, deposit settings, withdrawal settings, and [DeFi policy engine](/defi/defi-policy-engine.md), all of which are configured at the business line level. Each business line can have its own rules independently configured based on your risk requirements. The [Fund Security & Management](/fund-security-and-management/policy-engine.md) section walks through each setting.

***

## Accounts & Wallets

### Segregate Account (Warm and Cold)

Warm wallets offer comprehensive and convenient deposit and withdrawal capabilities, fully supporting daily asset management needs, including address library, gas station, batch transfer, wallet consolidation, and transaction acceleration. The [Deposit Features](/fund-security-and-management/deposit-features.md) and [Withdrawal Features](/fund-security-and-management/withdrawal-features.md) sections cover each of these in detail.

Cold wallets are stored in HSMs and kept fully offline. Cold wallet withdrawals can only be sent to warm wallet addresses within the same enterprise account. The Cactus Custody operations team processes cold wallet transactions, which takes 2 business days.

{% hint style="info" %}
To move assets from cold to warm storage, submit a cold wallet withdrawal order and approve it through the standard approval flow. The Cactus Custody operations team will then process the transaction. Once the funds arrive in your warm wallet, you can withdraw to external addresses as normal.
{% endhint %}

### DeFi Account

Supports interaction with DApps using Cactus Link. Each DeFi wallet can only have one address under it. Learn more about DeFi capabilities including Cactus Link, supported tokens, policy engine controls, and transaction management in the [DeFi](/defi/getting-started.md) section.

### Integrated Account

The Integrated Account provides access to the BIT (formerly known as Matrixport) trading platform for crypto-to-crypto trading. Each business line can have one Integrated Account balance wallet, where deposited assets are held and used for trading. Learn more in the [Integrated Account](/cefi-trading/crypto-to-crypto-trading-integrated-account.md) section.

### Fiat Account

Full Custody supports fiat currency custody in collaboration with Singapore Gulf Bank. This service must be enabled by the Cactus Custody operations team. Once activated, the administrator must acknowledge the service agreement and bind at least one enterprise same-name bank account before fiat operations can begin. See the [Fiat Custody](/full-custody-solution/fiat-custody.md) page for the full setup process and rules.

### Oasis Account

The Oasis Account is used for off-exchange settlement via Cactus Oasis. Each enterprise is assigned a single Oasis balance wallet. Assets can be deposited into this wallet and subsequently transferred to buffer accounts linked to supported exchanges for trading. Learn more in the [Cactus Oasis](/cefi-trading/off-exchange-settlement-cactus-oasis.md) section.

***

## Available Features

### Fund Management

* Segregated wallet architecture with dedicated on-chain addresses per client
* Customizable distribution of holdings between warm and cold storage

### DeFi Access

* [Interacting with DApps](/defi/interacting-with-dapps.md) across 1,000+ DApps on 30+ blockchains
* RWA and NFT management

### Trading

* Crypto-to-crypto trading via the [Integrated Account](/cefi-trading/crypto-to-crypto-trading-integrated-account.md)
* Fiat on/off ramp through Cactus [OTC](/cefi-trading/on-off-ramp-otc.md) service
* Off-exchange settlement via [Cactus Oasis](/cefi-trading/off-exchange-settlement-cactus-oasis.md)

### Earning

* [ETH Staking](/yield/eth-staking-via-cactus-custody.md) through a Staking-as-a-Service model with Paralinker and RockX
* [USDC Incentive Reward](/yield/usdc-incentive-reward.md) through Circle's MSCA program
* [DeFi yield opportunities](/yield/earning-via-defi.md) via Cactus Link

### Escrow

* Trusted [third-party digital asset escrow](/third-party-digital-asset-escrow/cactus-custody-third-party-escrow.md) for multi-party transactions

### Trust and Legacy

* Digital asset trust structures in partnership with Vistra for inheritance, asset protection, and wealth transfer. For details, refer to [Digital Asset Trust and Legacy](/digital-asset-trust-and-legacy/cactus-custody-digital-asset-trust-and-legacy.md).

***

## Audit & Report

Every system event and transaction is captured across all ledgers with precise timestamps, providing comprehensive audit trails across your entire custody environment.

* Historical records are protected from unauthorized modification or deletion, serving as a single source of truth for internal and external auditors
* Reports such as asset snapshots, order history can be generated on demand to meet the standards of global regulators
* Every administrative change and fund movement is signature-driven, providing a fully verifiable record for internal governance and regulatory reviews.

The [Audit & Report](/audit-and-report/audit-and-report-overview.md) section outlines the types of reports available, along with download permissions.

***

## Supported Assets

Cactus Custody supports 60+ blockchain ecosystems, covering all Top 50 public blockchains by market capitalization. Supported tokens vary across account types — not all tokens are available for every account type (Segregated Account - Warm, Segregated Account - Cold, DeFi Account, Oasis Account). Refer to the [Full Custody Supported Token List](https://www.mycactus.com/cactus/token-list) and check the corresponding column for each account type to confirm availability.
