Self-custody for companies: what it means day to day
A practical guide to corporate self-custody: how MPC key shares and quorum signing work, what providers can and cannot do, and how to plan approvals, recovery and counterparty risk.
For a company, self-custody means retaining control over the authority required to move its USDC or USDT. The assets remain on a blockchain address, and transfers require approval under the company’s signing policy rather than a withdrawal request to an exchange or custodian.
That does not mean one executive keeps a seed phrase in a safe. A modern self custody business setup can use a multi-party computation, or MPC, wallet with several approvers, transaction limits and recovery procedures. Stablerail business stablecoin accounts use self-custodial MPC vaults and quorum signing for this purpose.
Self-custody changes where risk sits. It reduces reliance on a provider to return assets on demand, but it gives the company more responsibility for signing access, approvals and disaster recovery.
How an MPC wallet works
A conventional crypto wallet signs transactions with a private key. Anyone who obtains that key can generally control the wallet. Losing it may make the assets permanently inaccessible.
An MPC wallet divides signing authority into cryptographic shares. Each share is held separately, and the parties cooperate to produce a valid signature without reconstructing or exposing a complete private key in one place.
This differs from simply splitting a seed phrase into pieces. MPC participants perform a signing process together. The resulting blockchain transaction looks like a normal transaction to the network, while the signing authority remains distributed behind the scenes.
A company might adopt a two-of-three quorum, meaning any two authorised participants must approve a transfer. The appropriate policy depends on the platform and configuration, but the principle is consistent: no single participant can act alone.
| Model | Who controls movement? | Main operational concern |
|---|---|---|
| Exchange account | The exchange controls blockchain keys and processes withdrawals | Withdrawal freezes, insolvency or account restrictions |
| Third-party custodian | The custodian holds signing authority under a custody agreement | Custodian availability, contractual terms and access procedures |
| Single-key self-custody | Whoever holds the private key or seed phrase | Theft, loss and dependence on one person |
| MPC self-custody | Participants acting under a defined quorum | Share availability, policy administration and recovery readiness |
What happens when finance sends a payment
Day to day, the process should resemble controlled business banking rather than manual interaction with private keys.
- Create the payment: A finance user enters the recipient address, token, amount and blockchain network. Batch files can be used for vendor, contractor or payroll runs where supported.
- Validate the details: The team confirms that the receiving wallet supports the selected asset and network. USDC on Ethereum and USDC on Solana, for example, are not interchangeable deposit instructions.
- Apply policy checks: Approval limits, address allowlists and sanctions or wallet screening can determine whether the payment proceeds or needs review.
- Collect quorum approvals: The required participants approve through their configured signing devices or applications.
- Broadcast the transaction: Once signed, it is submitted to the relevant blockchain. Network fees apply, and confirmation timing depends on the chain and current congestion.
- Retain evidence: The transaction ID, approvers, timestamps, screening results and invoice reference can be recorded in the audit log and evidence pack.
Stablerail supports stablecoin activity across Ethereum, Base, Arbitrum, Polygon, Tron, BNB Chain, Optimism and Solana. Network availability varies by asset, so finance teams should verify the token contract, destination network and fee asset before sending. Teams making recurring payments can also review stablecoin payout workflows.
What the provider can and cannot do
“Self-custodial” should describe the actual signing arrangement, not simply the user interface. Finance and security teams should document which party holds each share and which combinations can authorise a transaction.
Depending on the agreed configuration, the provider can typically supply the wallet infrastructure, construct transactions, enforce configured workflows, screen addresses, maintain logs and help coordinate recovery. It may also suspend access to its interface or services where legally required or where security controls are triggered.
Under a genuine quorum arrangement in which the provider does not control enough shares, it cannot unilaterally sign a blockchain transfer. It also cannot reverse a confirmed blockchain payment, recover funds sent to an incompatible address, or guarantee that a token issuer will not freeze an address. USDC and USDT issuers retain controls at the token-contract level.
Companies should not rely on a generic claim that “the customer controls the wallet.” Ask for a clear signing and recovery diagram covering:
- Who holds each key share.
- How many shares are needed to sign.
- Whether the provider can change the quorum or approvers alone.
- What happens if the provider becomes unavailable.
- Whether the company can move assets using an independent recovery route.
Disaster recovery is part of custody
A sound company crypto custody plan assumes that people leave, devices fail and providers experience outages. Recovery should be designed before the wallet receives a material balance.
Loss of one device or approver
If the remaining participants still meet the quorum, the company may continue signing while replacing the unavailable share through the platform’s approved process. Replacement should require identity checks and internal authorisation; it should not be treated as routine password reset.
Loss of enough shares to meet quorum
The recovery mechanism becomes critical. Depending on the architecture, this may involve an encrypted recovery share, an offline company-controlled component or a formal reconstitution process. The team should know the documents, participants and expected steps in advance. Recovery terms and timing should be confirmed with the provider rather than assumed.
Provider outage or failure
Ask whether transactions can be signed or recovered without the normal provider interface. If not, self-custody may reduce asset ownership risk while leaving significant operational dependency on the provider’s systems.
Run a recovery exercise at least annually and after major changes to directors, treasury staff or signing policy. Use a low-value wallet or controlled test rather than waiting for an emergency. Operational questions can be directed through Stablerail help.
How self-custody changes counterparty risk
With an exchange, the company usually owns a contractual claim against the exchange while the exchange controls the on-chain assets. A withdrawal can depend on the exchange’s solvency, controls, banking access and willingness or legal ability to process it.
Self-custody removes some of that exposure because the company’s quorum controls transfers from its blockchain address. Provider insolvency should not, by itself, give the provider authority to take the assets where the signing and recovery design is properly structured.
However, risk is not eliminated. It is redistributed:
- Operational risk: The company can approve the wrong address, network or amount.
- Access risk: Lost shares or unavailable approvers can delay or prevent payments.
- Stablecoin issuer risk: The issuer may freeze tokens, face reserve problems or change redemption access.
- Blockchain risk: Congestion, contract vulnerabilities and network incidents remain possible.
- Provider dependency: The interface, screening tools and recovery coordination may still depend on a service provider.
Fiat balances also follow a different legal and operational model from self-custodied stablecoins. Holding USDC in an MPC vault does not make a linked EUR or USD fiat balance self-custodial.
A practical setup checklist
- Choose a quorum that avoids one-person control without making routine payments impractical.
- Separate payment creation from final approval.
- Set approval thresholds based on payment value and risk.
- Allowlist recurring vendor and treasury addresses after independent verification.
- Document supported assets, networks and required fee tokens.
- Test a small transfer before sending a material amount to a new address.
- Record who holds each share without recording secret recovery material in the same document.
- Test device replacement and disaster recovery.
- Revoke or replace access promptly when an employee or director leaves.
- Reconcile on-chain balances and transactions with the accounting ledger.
The practical benefit of MPC self-custody is not the absence of controls or providers. It is the ability to define who can move company funds while avoiding dependence on one private key or a third party’s unilateral withdrawal process. The quality of the arrangement ultimately depends on its quorum design, recovery path and daily operating discipline.
Finance writers covering stablecoin treasury, payments, compliance, and risk controls.
More about the Stablerail team- Stablecoin treasury managementApprovals, limits, yield and reporting on one balance.
- Stablecoin payoutsBatch contractor and vendor payments with screening.
- USDT vs USDCWhich stablecoin your company should settle in.
- Stablecoin finance glossaryMPC, off-ramp, travel rule and the rest, in plain English.
- Product updatesEverything we ship, month by month.

