Purpose

Protect client fiat, virtual assets, access means and related data through the detailed SAFU segregation, movement, reconciliation, reporting, provider, technology and resolution controls, consistent with the approved Market Conduct & Trading Compliance Manual v1.1 section 6.

Steps

#ActionDetailsEvidence
1Maintain client fiat in segregated bank accounts and client virtual assets in wallets distinct from company holdingsClient fiat funds must be held in segregated bank accounts and virtual assets maintained in distinct wallets separate from company holdingsMCT 6.1 Dedicated Accounts
2Prohibit commingling or use of client assets for company operations, lending or proprietary tradingUnder no circumstances shall client assets be used to finance company operations, lending or proprietary tradingMCT 6.1 No Commingling
3Place client money in designated accounts within three calendar days, maintain one-to-one virtual-asset holdings and reconcile client entitlements at least weekly under the current modelSegregation practices will comply with jurisdiction-specific custody and safeguarding requirements including reporting to regulators where mandated; accurate records must be maintained to demonstrate full reconciliation of client balances at all times and independent audits may be conducted to verify complianceMCT 6.1 Regulatory Compliance, Auditability
4Apply approved wallet architecture, access controls, multifactor authentication, role-based permissions and approval workflowsThe firm will use a combination of multi-signature wallets, hardware security modules (HSMs) and cold storage solutions to safeguard client assets; only authorized personnel may access custody systems subject to multi-factor authentication, role-based permissions and approval workflowsMCT 6.2 Wallet Management, Access Controls
5Maintain secure backup, recovery, incident response, redundancy and business-continuity arrangementsCustody processes will include redundancies, secure backups and contingency procedures to ensure asset recovery in the event of technical failures or breaches (MCT 6.2 Operational Resilience); Bitkaya will maintain firewalls, intrusion detection systems, penetration testing and security monitoring to protect against cyber threats; client information and transaction records will be encrypted in transit and at rest with strict access controls applied; a formal incident response plan will be maintained including escalation procedures, forensic investigation and mandatory reporting of material breaches to regulators and affected clients; disaster recovery protocols, offsite backups and redundancy systems will ensure resilienceMCT 6.4
6Assess third-party custodians through due diligence, contract safeguards, information and audit rights and ongoing monitoringWhere third-party custodians are used, they will be subject to rigorous due diligence, contractual safeguards and ongoing monitoringMCT 6.2 Vendor Oversight
7Assess insurance availability, scope, limitations and adequacy regularly and disclose material protection limitations to clientsPolicies may include protection against cyberattacks, fraud, employee misconduct and operational failures; clients will be informed of the extent and limitations of any insurance coverage to ensure clarity about protections; the firm will regularly assess the adequacy of insurance arrangements in line with evolving risks, market conditions and regulatory guidanceMCT 6.3
8Apply documented holds or restrictions where law, sanctions, unusual-activity review, fraud or safeguarding concerns require themClient assets must be safeguarded, but may also need to be restricted, held or prevented from moving where applicable law, sanctions controls, unusual activity review, fraud concerns or other legal restrictions require this; such matters must be managed through documented escalation and decision-making proceduresMCT 6 intro
9Issue monthly client statements within 25 calendar days of the statement date and investigate client discrepancies promptly
10Investigate reconciliation, access, security or asset exceptions immediately and escalate material matters

Exceptions and Escalation

Any unexplained reconciliation difference, unauthorized access, commingling, custody weakness or failed recovery control requires immediate escalation and restriction of affected activity.

Records

  • Segregated account and wallet inventory
  • Reconciliations and exception resolution
  • Access and approval records
  • Custody design and third-party oversight
  • Insurance assessment and disclosure
  • Incident, restriction and recovery evidence

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: continuous safeguards, scheduled reconciliation and periodic risk review

History

  • 2026-07-26: Created from section 6 of the approved MCT Manual.
  • 2026-07-26: Linked to the detailed SAFU framework and aligned explicit operating frequencies.