Objective

Ensure client money and virtual assets remain separate, identifiable, clearly labeled and fully matched to client entitlements. Enforce strict segregation between client assets and the company’s own funds and holdings, safeguarding them from misuse, misallocation, or loss in the event of financial distress or insolvency.

Control Activity

Operations places client money into designated Client Account bank accounts titled “Client Account” used exclusively for holding client money, separate from Bitkaya’s own funds, within three (3) calendar days of receipt. Bitkaya does not deposit its own funds into a Client Account wallet except to meet a temporary shortfall under exceptional and documented circumstances. Operations maintains designated Client VA Wallets labeled “Client VA Wallet” in Bitkaya’s records, used exclusively for holding client virtual assets, separate from Bitkaya’s own virtual assets. Client VA holdings are maintained on a strict one-to-one basis ensuring balances in custody always match client entitlements. Commingling is prohibited: one client’s money or virtual assets must never be used to satisfy another client’s obligations or Bitkaya’s own operational needs. Lending, staking, or other financial activities using Client VAs are prohibited unless explicit prior client consent is obtained and Bitkaya has appropriate licensing. Proceeds (airdrops, staking rewards, or other network-based distributions) accrue to the client’s benefit unless explicitly agreed in writing. Bitkaya does not assume ownership rights over client VAs except where assets are placed under trust with clients as ultimate beneficiaries. Operations immediately restricts and escalates any shortfall, commingling, unclear ownership or misallocation.

Verification Requirements

  • Verify that Client Account bank accounts are titled “Client Account” and used exclusively for holding client money, separate from Bitkaya’s own funds.
  • Verify that Client VA Wallets are labeled “Client VA Wallet” in Bitkaya’s records and used exclusively for holding client virtual assets, separate from Bitkaya’s own virtual assets.
  • Verify that client money receipts are placed into a designated Client Account within three (3) calendar days of receipt.
  • Verify that Bitkaya’s own funds are not deposited into a Client Account wallet except under exceptional and documented circumstances for a temporary shortfall.
  • Verify that client VA holdings are maintained on a one-to-one basis against recorded client entitlements, with no shortfalls.
  • Verify that no client money or virtual assets belonging to one client are used to satisfy another client’s obligations or Bitkaya’s operational needs.
  • Verify that any lending, staking, or other financial activities using Client VAs have explicit prior client consent and appropriate Bitkaya licensing.
  • Verify that proceeds (airdrops, staking rewards, or other network-based distributions) accrue to the client’s benefit unless explicitly agreed in writing.
  • Verify that Bitkaya has not assumed ownership rights over client VAs except where assets are placed under trust with clients as ultimate beneficiaries.
  • Verify that any commingling, shortfall, unclear ownership or misallocation is immediately escalated and affected activity is restricted.

Evidence

  • Expected evidence: Account, wallet and entitlement inventory
  • Expected evidence: Three-day placement evidence
  • Expected evidence: One-to-one holding evidence
  • Expected evidence: Consent and legal authorization for exceptional use
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample receipts and balances and trace them to segregated holdings and client entitlements
  • Testing frequency: per receipt and continuous holding requirement

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved SAFU Manual.