CustodyPrimo, operated by Capital Asset Management Limited HK, provides institutional-grade custody of digital assets for individual and institutional clients. This policy explains how we safeguard, segregate and administer client assets.
1. Scope
This Custody Policy applies to all digital assets held by CustodyPrimo on behalf of clients under a custody or related service agreement. It describes our custody model, security architecture, and the controls that protect client assets.
2. Custody model
Client assets are held predominantly in cold storage — offline, air-gapped environments protected by hardware security modules (HSMs), biometric access controls and multi-signature authorization. A limited operational balance may be held in secured warm infrastructure to support timely withdrawals and settlement.
Our key-management infrastructure uses Multi-Party Computation (MPC), which eliminates single points of failure. Transaction signing requires multiple approvals from distributed, encrypted devices held under strict role separation.
3. Segregation of client assets
- Client digital assets are recorded as belonging to clients and are held separately from the firm's own assets.
- Internal ledgers reconcile to on-chain balances on a continuous basis.
- Client assets are not lent, rehypothecated or otherwise used for our own account except where you have expressly opted into a separate service (for example staking) under its own terms.
4. Access controls & authorization
Access to custody systems is governed by least-privilege principles, multi-factor authentication, and separation of duties. Withdrawals require multi-party authorization, address allow-listing where enabled, and are subject to velocity and threshold controls.
5. Compliance, auditing & insurance
Our custody operations are designed to meet recognised standards including SOC 2 and ISO 27001, and are subject to regular independent security testing and audit. Eligible client assets are covered by comprehensive insurance against theft, loss and breach, subject to the terms, limits and exclusions of the applicable policy.
6. Business continuity & key recovery
We maintain geographically distributed, encrypted key material and documented recovery procedures so that client assets remain recoverable in the event of hardware failure, site loss or personnel unavailability. Business-continuity and disaster-recovery plans are tested periodically.
7. Your responsibilities
- Keep your account credentials and authentication devices secure and confidential.
- Verify withdrawal addresses carefully — blockchain transactions are irreversible.
- Notify us immediately of any suspected unauthorized access.
8. Contact
Questions about this policy or your custody arrangements can be directed to info@custodyprimo.com.
This document forms part of the CustodyPrimo terms that govern your use of our services. It should be read together with our other disclosures. If any provision conflicts with our Terms & Conditions, the Terms & Conditions prevail. We may update this document from time to time; the current version is always published on this page.