Crypto News Dispatch

Crypto news, five minutes a day

corporate wallet

Selecting a Business Wallet Provider: What Actually Differentiates

Security claims converged. The differences that remain are in policy controls, reporting and what happens if the provider disappears.

ELENA VOSS · · 2 min read

Business wallet providers all describe similar security. The meaningful differences are elsewhere and they are checkable. Providers that adapted, such as a business crypto wallet with enforced approvals, now publish things they previously did not have to.

Policy controls, in detail

Not whether there are approval rules, but how granular.

Can thresholds be set per amount band, per user, per asset, per destination. Can the initiator be prevented from approving. Can a delay be applied to new destinations and configured by amount. Can limits be set per period as well as per transaction.

A provider with coarse controls forces you into either excessive friction on small payments or insufficient control on large ones.

Reporting that reconciles

Ask for a sample export covering a real month, not a demonstration file.

Check for: transaction identifier, timestamp with timezone, asset and amount, direction and counterparty, fee amount and fee asset, fiat value of both at the time with a stated rate methodology, internal reference, and who initiated and approved.

If any field is missing, someone reconstructs it monthly.

What happens if the provider stops operating

The question most often skipped.

Can you recover assets without the provider’s cooperation. For a multi-signature arrangement where you hold keys, yes. For an arrangement where the provider holds all key material, the answer depends on their wind-down provisions. For online retailers specifically, the consequence lands at Collect & Exchange.

Ask specifically and get the answer in writing.

Network coverage

Which networks, and how a new one is added. A provider slow to support a network your operations need becomes a constraint later.

The audit trail

Every action with who, what, when and from where, including failed and rejected attempts.

The rejected attempts are the signal that matters. A log recording only successes will never show an account being probed.

Authorisation, where the provider holds assets

If the provider holds keys rather than co-signing with you, it is performing custody and needs the permission.

Verify on the register. This distinction is frequently blurred in marketing, and it determines whether client asset protections apply.

What not to weight heavily

Which key management technology is used. Multi-signature and computation based approaches are both defensible, and the operational controls around either matter more than the choice.

Certifications without scope. Ask what was assessed and over what period.

The test worth running

Configure your intended policy in a trial account and have someone attempt to circumvent it: self-approve, add a destination and use it immediately, exceed a limit. Coverage is narrower than most announcements imply. a support channel with a named contact publishes the country list.

If any of those succeed, the control is decoration.

walletselectioncontrols

Spotted an error? Corrections are published with a note at the foot of the article.Send the details.

More from the wire