PLAYBOOK
Custodial vs non-custodial: which model to choose
A B2B guide to custodial vs non-custodial crypto custody, and how choosing a non-custodial wallet changes your risk, compliance and licensing profile.
PLAYBOOK
A B2B guide to custodial vs non-custodial crypto custody, and how choosing a non-custodial wallet changes your risk, compliance and licensing profile.
Every founder building a crypto and fiat product hits the same fork early, and it is not a UI decision. It is who holds the keys. That single choice shapes your security posture, your liability, your licensing conversation and how a partner bank or auditor will view you.
The word “custody” causes confusion because it sounds like a storage question. It is really a control question. Whoever controls the private keys controls the money, no matter which brand name sits on the app. This guide breaks down the two models, walks through the reasons a non-custodial wallet fits B2B infrastructure, and lists what to weigh before you commit. For the wider build, see the pillar on how to build a crypto and fiat payment platform.

Custody is the control of private keys. In a custodial model a third party holds those keys and can move funds for the user. In a non-custodial model the user holds their own keys and every movement needs their approval. Everything else, wallet type, security stack, insurance, follows from that one distinction.
Here is the comparison at a glance.
| Dimension | Custodial | Non-custodial |
|---|---|---|
| Who holds the keys | The provider or platform | The end user |
| Who approves a transfer | The provider, on the user’s behalf | The user signs each movement |
| Counterparty risk | Concentrated in the provider | Removed at the provider level |
| Safeguarding burden | On the provider’s balance sheet | Reduced at the provider level |
| Typical licensing exposure | Higher (holding client funds) | Often lower (agent of licensed partners) |
| Recovery if keys are lost | Provider can often help | Depends on the user’s backup |
| Best fit | Simplicity, managed treasury | Control, lower regulatory surface |
Neither column is universally correct. The right answer depends on what you are building, who your users are and which markets you serve. What follows is why non-custodial has become the default for B2B payment infrastructure, and where custodial still earns its place.
When users hold their own keys, you are not a pooled honeypot of client funds. The single largest failure mode in this industry, a platform that is hacked or becomes insolvent and cannot return balances, does not apply the same way when you never hold the money. Users carry their own asset directly rather than a claim against you.
Holding customer funds pulls you squarely into safeguarding and money-transmission rules. A non-custodial design means you never take custody, which for many products is the difference between needing a heavyweight licence yourself and operating as an agent of licensed partners. It does not erase compliance, but it changes the conversation. Map this perimeter with counsel early, and see our guide on licensing to move crypto and fiat.
The less customer money that touches your balance sheet, the smaller your attack surface and your audit scope. You still run serious security, but you are protecting infrastructure and access, not a central vault of everyone’s assets. That is a materially easier posture to defend to a partner bank.
Non-custodial is not a compliance shortcut. KYC and KYB at onboarding, sanctions and PEP screening, transaction monitoring and travel-rule data still apply. The point is that a non-custodial architecture lets those controls run in the flow without also making you the safekeeper of client funds. For how these checks work end to end, read how KYC and AML work for crypto and fiat payments.
A common myth is that non-custodial means limited. It does not. A card can spend directly from a non-custodial balance, with the wallet connected to the card network so purchases settle against the real-time balance, plus limits, freeze controls and 3-D Secure. See card issuing that spends from a crypto or fiat balance.
After several high-profile platform failures, “not your keys, not your coins” is now a mainstream expectation, not a niche slogan. Offering genuine control is a trust signal, and for many B2B customers it is a procurement requirement rather than a nice-to-have.
Non-custodial is not free of trade-offs. Weigh these honestly.
If a user loses their keys and their recovery material, funds can be unrecoverable. Custodial providers can often reset access; pure self-custody cannot. Modern schemes such as multi-party computation and social or policy-based recovery soften this, but recovery design is now your responsibility, not an afterthought.
Asking users to approve every movement and guard a recovery phrase adds friction. Good non-custodial products hide the cryptography behind clean flows and sensible defaults, but you must design for the moment a non-technical user faces a signing prompt or a backup step.
Managed treasury, certain regulated products, and flows where a business must move client funds on their behalf can require a custodial or regulated-custodian arrangement. The honest answer is that many platforms end up with a hybrid, non-custodial for user balances and a regulated custodian for specific pooled or institutional funds.
Even non-custodial, a B2B platform handling any operational or client-adjacent funds needs clean segregation, auditable movement and clear treasury policy. Non-custody reduces the surface; it does not remove your duty to run funds cleanly and prove it on demand. This pairs naturally with multi-currency accounts and a unified ledger.
A wallet is just where keys live and how they sign. The choice is a balance between how often funds move and how much is at stake.
| Wallet type | Connectivity | Typical use | Trade-off |
|---|---|---|---|
| Hot wallet | Online | Active balances, frequent movement | Convenient, larger attack surface |
| Cold wallet | Offline | Long-term holdings, reserves | Very secure, slower to use |
| Hardware wallet | Offline device | Personal and treasury holdings | Strong key isolation, physical to manage |
Most serious setups combine them: a small hot balance for day-to-day flow and the bulk in cold or hardware storage. The same logic applies to a business treasury, where operational float sits hot and reserves stay cold.
Custody security is mostly about how signing authority is protected and split. Three techniques dominate, and they can be combined.
For an infrastructure provider, the goal is that no single device, server or employee can move funds unilaterally, and that every approval is policy-driven and logged. These techniques serve both custodial and non-custodial designs; the difference is who sits inside the approval policy.
Custody choices are inseparable from regulation, and the rules vary by market. As a general principle, jurisdictions increasingly distinguish between platforms that hold client crypto (which attracts safeguarding, capital and reporting duties) and non-custodial software that never controls user funds.
In Mexico, virtual asset activity sits within the Fintech Law framework, with the CNBV and Banco de México as the relevant authorities, and holding or operating virtual assets on behalf of clients carries specific obligations. Treat this as a general orientation only, because thresholds, authorizations and the exact perimeter change over time and by activity. Confirm the current position for your model with local regulatory counsel before you rely on it.
Two points hold across markets. First, regulated or “qualified” custodians exist precisely for institutions that must delegate custody under supervision, often with insurance over assets under custody, though coverage terms and limits vary and should never be assumed. Second, whichever model you pick, KYC, AML and monitoring obligations follow the activity, not the custody label.
Whatever model you land on, a few practices are non-negotiable.
Tokelia is built non-custodial by design: end users keep control of their own funds and every movement needs their approval, so you launch a real payment product, virtual accounts, unified crypto and fiat rails, card issuing and cross-border payments, without holding customer money on your balance sheet. Compliance is built into the base stack rather than sold as add-ons. Money services are provided by Tokelia LLC, a company registered as a Money Services Business with FinCEN, with regulated banking delivered by licensed institutions.
If you are weighing custodial against non-custodial for your own product, the fastest way to pressure-test it is to walk a real flow with our team. Talk to us and we will map it to your use case and markets.
Crypto custody is the practice of holding and safeguarding the private keys that control digital assets. Whoever holds those keys can move the funds, so custody is really a question of who controls the keys, not where the tokens appear to sit. It splits into two models, custodial (a third party holds the keys) and non-custodial (the asset owner holds the keys).
In a custodial model a third party holds the private keys and can move funds on the user's behalf. In a non-custodial model the user holds their own keys and must approve every movement. The practical difference is control and liability, because whoever holds the keys carries the safeguarding, security and often the regulatory burden that comes with them.
Leaving assets on a third-party platform is convenient but concentrates counterparty risk, because you hold a claim against that platform rather than the asset itself. If the platform is hacked, becomes insolvent or freezes withdrawals, your access depends on its solvency and its controls. For meaningful balances, many businesses reduce this exposure with self-custody or a regulated custodian and clear segregation of client funds.
A non-custodial wallet is one where the private keys stay under the user's control rather than a provider's. The provider can offer the software, the interface and the security tooling, but cannot move funds without the user's signature. This design reduces the provider's safeguarding surface and gives the end user direct control of their assets.
There is no single safest place, only trade-offs between control, convenience and operational risk. Long-term holdings are often kept in cold or hardware wallets offline, active balances in hot wallets, and institutional funds with a regulated custodian using MPC or multisig. The safest setup matches the storage method to how often the funds move and how much is at stake.
Self-custody, also called non-custody, means the asset owner holds their own private keys and is solely responsible for approving transactions and protecting the recovery material. It removes reliance on a third party to move funds, which lowers counterparty risk but shifts full responsibility for key security and backups onto the owner.
Custody works by controlling the cryptographic keys that authorize transactions on a blockchain. Providers protect those keys with techniques such as hardware security modules, multi-signature schemes and multi-party computation, and layer on access controls, approval policies and monitoring. Whether the arrangement is custodial or non-custodial depends on who ultimately holds the signing authority.
Topics
Written by
LucíaCompliance & Regulatory
Lucía covers compliance and regulation at Tokelia. She writes about the licensing, KYC/AML and travel-rule questions that come up when a fintech starts moving crypto and fiat, and turns them into decisions a founding team can act on.
Tell us your use case and we’ll point you to the right layer: infrastructure, tokenization or Yakopay.
We use essential cookies to run this site and, only with your consent, analytics cookies to measure traffic. You can change your choice anytime. Cookie Policy