Security and Asset Custody Policy
Last updated: July 2026
This document describes the core principles of TINQ's policy for securing digital assets held on behalf of its customers, and the custody model employed.
1. The Custody Model
Customer assets are held in managed custody at BitGo, an institutional custody provider specializing in digital asset security, which combines cold storage infrastructure with institutional bank-level security controls. Full details on the difference between a cold wallet and a hot wallet appear on the "Security & Privacy" page of the site.
2. Segregation of Customer Assets
Customer assets are managed separately from the company's own assets, so that at any time the balance of digital assets can be identified and attributed to each customer individually. This segregation is intended to ensure that customer assets are not exposed to the company's own credit or operational risks.
3. Cold Wallet vs. Hot Wallet
The vast majority of digital assets are held in cold wallets, physically disconnected from the internet and inaccessible to remote cyberattacks. A small, limited balance is held in a hot wallet for the ongoing operation of withdrawal and deposit requests within a reasonable time.
4. Internal Access Controls
Access to custody systems is subject to multi-layered controls, including Multi-Factor Authentication, Multi-Signature for material actions, and segregation of duties between different permission holders in the organization.
5. Asset Insurance
Customer assets held in custody are covered by institutional insurance arrangements against theft, hacking, and loss of private keys, in accordance with the terms of the relevant policy in effect. Exact insurance coverage details are available for review upon request and subject to relevant confidentiality agreements.
6. Monitoring and Incident Response
The company's systems are monitored on a 24/7 basis to detect unusual activity or unauthorized access attempts, and there is an Incident Response plan activated immediately when needed, including temporary freezing of activity and updating relevant customers.
7. Business Continuity and Backup Procedures
The company maintains backup and Business Continuity procedures that ensure that in the event of a technical failure or unusual incident, access to customer data and assets can be restored within a reasonable time, in accordance with the company's internal policy.
8. Policy Updates
This policy is reviewed and updated periodically in accordance with technological and regulatory developments, and based on the company's ongoing risk assessment.