Custody platforms

The substrate your customers verify directly

Build on an open, extensible custody stack. Extend the policy logic with your own modules, and integrate at the layer that fits: smart contracts, our indexing and routing infrastructure, or our execution interfaces.

The problem

You’re building a product where other companies' treasuries or users hold funds. Building the custody and policy infrastructure in-house is a quarter-long detour from your product. The off-the-shelf shortcut puts another vendor in the trust path of every transaction, and boxes you into whatever feature set that vendor decided to ship.

What to look for

What your engineering and customer teams need

  • Extensibility

    Can you extend the policy logic with your own modules, or are you locked to a fixed feature set? Does it compose with the onchain protocols you already build on?

  • Integration surface

    Can you adopt it at the layer that fits your stack: the smart contracts directly, shared indexing and routing infrastructure, or a full execution interface?

  • No platform lock-in

    Your customers must be able to leave with their funds. You must be able to swap providers without breaking your product surface.

  • Audit and compliance

    Your customers will ask. The provider’s audits, the contracts’ audits, regulatory posture, certifications.

What Zodiac does

Open and extensible, with no vendor in the trust path

  • Extend it with your own modules

    Zodiac’s policy logic is modular and open. Write your own modules to extend it, and compose with other smart contracts like DeFi lego bricks. You are never boxed into a fixed feature set.

  • Integrate at any layer

    Adopt Zodiac purely on the smart contract layer, on top of our high-performance indexing and routing infrastructure, or at the interface level by integrating directly with our app and execution interfaces.

  • Cannot drain customers, by construction

    Your platform structurally cannot move funds outside what the customer permits. The limit holds even if your own systems are compromised, so customers can verify it rather than take your word for it.

  • Open contracts, composable compliance

    Audited by G0 Group, Omniscia, and Gnosis. Composable with the compliance vendors your customers will ask for.

Case study

Gnosis Pay, live in production

Gnosis Pay is a self-custodial debit card. It runs on exactly this pattern, in production today.

  • Each user gets a Safe they fully own
  • A tightly scoped role lets the card processor withdraw stables when the user pays a merchant, and nothing else
  • The user’s card spending limits are enforced onchain by Zodiac, not by the processor’s backend

The processor can settle a card payment, but it cannot move funds anywhere else, cannot exceed the user’s limit, and cannot touch the rest of the balance. Even if the processor’s systems are compromised, the worst case is bounded by the role. The user holds their own keys the whole time. Nobody can drain them, because the chain wouldn’t let it through.

Want to walk through your specific operating model?