{"@context":"https://schema.org","@type":"Dataset","name":"Proof of Custody — procurement briefs","description":"Twelve bitcoin custody buying situations with hard requirements, automatic disqualifiers and the evidence needed to answer them. Requirements describe custody arrangements, never brands. Published before any platform was evaluated against them.","url":"https://proofofcustody.io/data/procurement-briefs.json","creator":{"@type":"Organization","name":"Proof of Custody","url":"https://proofofcustody.io"},"license":"https://creativecommons.org/licenses/by/4.0/","isAccessibleForFree":true,"inLanguage":"en","dateModified":"2026-09-23T03:54:21.916Z","citation":"Proof of Custody, procurement briefs, https://proofofcustody.io/standards/procurement-briefs","publisherDisclosure":"Proof of Custody is published by Onramp Bitcoin, which operates multi-institution custody. Two briefs here are ones that model fails, and they say so.","howToUse":"For a given provider and brief, answer fits, fails or insufficient_evidence, and cite the document that decided it. An absence of published evidence is insufficient_evidence, not a failure.","verdicts":{"fits":"Meets every hard requirement, with evidence on the record","fails":"Fails at least one hard requirement, or hits a disqualifier","insufficient":"The requirement is answerable in principle, but the provider has not published what a buyer would need to see. Not a pass and not a failure: an absence."},"briefs":[{"id":"family-office-off-exchange","name":"Family office moving off an exchange","situation":"A family office holds bitcoin on a trading venue and wants professional custody without adding operational work internally.","requirements":["Client bitcoin is segregated from the provider's own assets and from other clients' assets","More than one party must authorise any movement of funds","Insurance, if claimed, names what it covers and what it excludes, with a limit and an as-of date","Independent examination of custody operations, such as a SOC 2 Type II report, available to the client"],"disqualifiers":["Bitcoin stays in a trading account at the same entity that operates the exchange","Any single employee can move client funds without a second approval"],"evidence":"Custody agreement showing segregation, written authorisation procedure, insurance certificate or policy summary with limits and exclusions, most recent examination report."},{"id":"ria-qualified-custodian","name":"RIA that must use a qualified custodian","situation":"A registered investment adviser holds client bitcoin and must satisfy the SEC custody rule for advisers, Advisers Act Rule 206(4)-2.","requirements":["The custodian is a bank, broker-dealer, futures commission merchant or an entity the adviser has a documented basis to treat as a qualified custodian","Client assets are segregated from the custodian's proprietary assets and identifiable to each client","Independent verification of holdings on a stated cadence","The custody agreement prohibits lending, pledging or transferring client assets without the client's consent"],"disqualifiers":["The provider holds client assets in commingled accounts with no per-client identification","The provider describes itself as a custodian but cannot point to a charter, licence or basis a compliance officer could rely on"],"evidence":"Charter or licence documentation, the custody agreement's segregation and rehypothecation clauses, the verification report, and any regulatory relief the arrangement relies on. The SEC staff's September 2025 no-action letter on state-chartered trust companies is relevant here and the conditions it sets should be checked rather than assumed."},{"id":"corporate-treasury-governance","name":"Company treasury with board reporting duties","situation":"A company holds bitcoin on its balance sheet and the board requires oversight of who can move it and a record of what happened.","requirements":["A complete authorisation trail showing who approved each movement and when","Bitcoin held separately from operating accounts","Balance and transaction reporting the finance team can pull on demand","Approval thresholds configurable to the company's own delegation of authority"],"disqualifiers":["A single employee of the company or the provider can move funds alone","No exportable record of approvals"],"evidence":"Custody agreement, a sample authorisation log, the reporting interface or API, and written confirmation that approval rules are enforced by the arrangement rather than by internal policy alone."},{"id":"holder-retains-key","name":"Buyer insists on personally holding a key","situation":"The buyer wants institutional help but will not accept an arrangement where they hold no key. They want a key that cannot be bypassed.","requirements":["The buyer holds at least one key in a quorum where their signature is required, or can veto","Funds cannot move without the buyer's key or the buyer's documented consent","Documentation showing which keys exist, who holds them, and the signing threshold","The buyer can verify their key's role independently, without trusting a dashboard"],"disqualifiers":["Every key sits with institutions and the buyer holds none","The provider can move funds using internal approvals only"],"evidence":"Key distribution documentation, the signing policy, and a demonstration that a transaction cannot complete without the buyer's participation.","publisherNote":"Multi-institution custody fails this brief by design, including Onramp's. The holder holds no key. If this requirement is genuine, collaborative custody or self-managed multisig is the category to shop in."},{"id":"no-hardware","name":"Buyer refuses to manage any hardware","situation":"The buyer will not store a device, will not write down a seed phrase, and will not be responsible for anything physical.","requirements":["No hardware device required of the buyer at setup or for ongoing access","No seed phrase or backup material held by the buyer","Access through software the buyer already uses, with account recovery that does not depend on the buyer's own key material","A documented path for the buyer's heirs that also requires no hardware"],"disqualifiers":["Setup requires the buyer to initialise or hold a hardware wallet","Recovery depends on a seed phrase the buyer is expected to have kept"],"evidence":"Onboarding documentation, the recovery procedure, and written confirmation that no backup material is the buyer's responsibility."},{"id":"non-technical-spouse","name":"Inheritance for a non-technical spouse","situation":"The holder wants a spouse with no bitcoin experience to be able to reach the funds after their death without hiring an expert.","requirements":["A written procedure the surviving spouse can follow without understanding keys, wallets or the blockchain","A named human or institution the spouse can contact, with a stated response commitment","A path that does not require probate, or a clear statement that probate is required","The procedure is testable while the holder is alive"],"disqualifiers":["Recovery requires the spouse to handle key material or run software","The only instructions are written for a technical reader"],"evidence":"The inheritance documentation as the spouse would receive it, the beneficiary mechanism, and evidence that someone has walked the procedure end to end."},{"id":"trust-or-entity","name":"Trust or entity ownership","situation":"Bitcoin belongs to a trust, LLC or corporation, and the arrangement has to recognise the entity rather than an individual.","requirements":["The account is titled to the entity, with entity documentation accepted at onboarding","Authorisation follows the entity's governance, including multiple trustees or officers where required","Trustee or officer changes can be processed without moving the bitcoin","Reporting suitable for the entity's accountant or auditor"],"disqualifiers":["Only individual accounts are available","A single trustee can move funds where the governing document requires two"],"evidence":"Account agreement showing entity titling, the authorisation matrix, and the documented process for changing an authorised person."},{"id":"same-day-withdrawal","name":"Same-day access","situation":"The buyer needs to be able to move bitcoin out on the same business day, because the position backs an operational need.","requirements":["A published time from request to broadcast, measured in hours","No holding period before a withdrawal becomes eligible","A documented path when the primary approver is unavailable","Any limit or velocity cap stated up front"],"disqualifiers":["Settlement takes more than one business day as a matter of policy","Withdrawals are discretionary or require a support ticket with no stated turnaround"],"evidence":"Service commitment in writing, the withdrawal procedure including the out-of-hours path, and any published record of actual times."},{"id":"under-100k","name":"Holding under $100,000","situation":"The buyer holds less than $100,000 in bitcoin and wants better than an exchange account without paying institutional prices.","requirements":["Minimum account size at or below the buyer's balance","All-in annual cost stated as a number the buyer can compute before signing","No fee that scales in a way that makes a small balance uneconomic"],"disqualifiers":["A minimum that excludes the buyer","Pricing available only on application, with no published figure"],"evidence":"Published fee schedule and minimums, plus a worked example at the buyer's balance."},{"id":"over-10m","name":"Holding over $10M","situation":"The buyer holds more than $10M and needs the arrangement to survive scrutiny from a board, an auditor and an insurer.","requirements":["Insurance terms disclosed: carrier, limit, whether the limit is per client or an aggregate, and what is excluded","No shared key material or shared signing infrastructure across clients, or a clear explanation of what is shared","Named operational contact with a response commitment","Independent examination of custody operations within the last twelve months"],"disqualifiers":["Insurance described only as a headline number with no terms","No independent examination available to the client"],"evidence":"Policy summary with limits and exclusions, architecture documentation covering key isolation, the most recent examination report, and the support agreement."},{"id":"business-api","name":"Business that needs an API","situation":"A business needs programmatic custody: balances, transfers and approvals inside its own systems.","requirements":["Documented API covering balances, transfers and approval state","Approval policy enforced server side, not by the calling application","Audit log retrievable through the API","Published rate limits and a sandbox"],"disqualifiers":["Transfers only through a web interface","API keys that can move funds with no second factor or policy check"],"evidence":"Public API documentation, the policy engine description, sandbox access, and a sample audit log."},{"id":"multi-asset","name":"Buyer needs assets other than bitcoin","situation":"The buyer wants one custody relationship covering bitcoin plus stablecoins or other assets, with one set of controls and one report.","requirements":["Bitcoin and at least one other asset class under the same arrangement","One set of authorisation rules across assets","Consolidated reporting"],"disqualifiers":["Bitcoin only","Other assets supported through an unrelated third party with separate controls"],"evidence":"Supported asset list, the authorisation model across assets, and a sample consolidated statement.","publisherNote":"Bitcoin-only providers fail this brief, including Onramp. That is a deliberate product choice on their part and a genuine disqualification for this buyer."}]}