Fystack Partners with Securosys to Deliver HSM-Backed Custody for Regulated Institutions

Fystack today announced a partnership with Securosys, a Swiss leader in Hardware Security Modules (HSMs), to expand its custody platform with an HSM-backed deployment option for banks and institutional clients.
The partnership extends Fystack's existing MPC-based custody architecture, giving institutions the flexibility to choose the security model that best aligns with their operational, security, and compliance requirements.
Key takeaway: MPC remains Fystack's default architecture for most deployments. Through its partnership with Securosys, Fystack now also supports HSM-backed custody for organizations that require certified hardware.
How the Fystack Custody Platform Works
Custody is more than key storage. Institutions running digital asset operations day to day rely on a full orchestration layer sitting on top of the keys themselves:
- Wallet lifecycle management - creating, organizing, and governing wallets across users, teams, and treasury accounts
- Policy engine - configurable rules defining who can move which assets, under what conditions
- Approval workflows - multi-sig and role-based approval groups for transaction sign-off
- Audit trails - a full record of every action taken across the platform
- Blockchain connectivity - multi-chain transaction orchestration across ETH, Solana, Base, Tron, and more
This orchestration layer stays the same regardless of which security architecture sits underneath it. What changes is how the keys themselves are protected, and that's what this partnership adds.
Why This Partnership Matters
While MPC meets the needs of most fintechs and payment companies, some regulated institutions operate under internal security policies or procurement standards that require certified hardware.
By integrating Securosys Primus HSM into the Fystack custody platform, Fystack can now support both deployment models without changing the operational layer customers use every day.
Securosys brings industry-recognized certifications to this integration. Primus HSMs are FIPS 140-2 Level 3 and Common Criteria EAL4+ certified, with FIPS 140-3 Level 3 certification currently in progress. The same technology is trusted by SIX, the operator of Switzerland's national interbank payment system under the oversight of the Swiss National Bank.
MPC vs HSM-Backed: How They Compare
| Fystack MPC (default) | Fystack HSM-backed (Securosys) | |
| Best fit | Most fintechs, payment companies, Web3 businesses | Banks and institutions with certified-hardware requirements |
| Key protection | Distributed across MPC parties, no single party holds a full key | Generated, stored, and used entirely inside certified HSM hardware |
| Deployment | Self-hosted (no dedicated HSM required) | Self-hosted, paired with dedicated HSM hardware |
| Orchestration layer | Same policy engine, approvals, audit trails | Same policy engine, approvals, audit trails |
Use Cases
Whether running on MPC or HSM-backed architecture, Fystack's custody platform supports:
- Cross-border payments - settlement infrastructure with policy-controlled transaction approval
- On/off-ramps - fiat-to-crypto and crypto-to-fiat flows with full audit trails
- Digital asset exchanges - exchange custody backed by approval workflows and access controls
- Tokenization platforms - infrastructure for RWA tokenization, tokenized deposits, and stablecoin issuance
About Fystack
Fystack provides wallet and custody infrastructure for payment companies, fintechs, and enterprises building on stablecoin rails and tokenized assets. Fystack helps traditional financial institutions access blockchain without needing an in-house Web3 or crypto team. Through its partnership with Securosys, Fystack now supports both MPC-based and HSM-backed custody architectures.
About Securosys
Securosys SA, based in Zurich, is a global leader in cybersecurity and digital identity protection. Their Swiss-built HSMs,trusted by over half of Tier 1 banks, secure critical infrastructure, and support PQC. Certified to the highest standards andavailable on-premises or as cloud-based solution.
Need HSM-backed digital asset custody for your institution? Contact the Fystack team.
Frequently Asked Questions
Does Fystack always use HSM for custody?
No. MPC is Fystack's default architecture for most deployments. Through our partnership with Securosys, we can now offer HSM-backed custody as a deployment option for institution such as bank, who require certified, tamper-resistant hardware.
What is the difference between MPC and HSM-backed custody on Fystack?
Both run on the same orchestration layer, including the policy engine, approval workflows, and audit trails.The difference lays in how the keys are protected: MPC distributes key generation and signing across multiple parties, while HSM-backed custody generates, stores, and uses keys entirely inside certified, tamper-resistant hardware.
What certifications do Securosys HSMs hold?
Securosys Primus HSMs are FIPS 140-2 Level 3 certified and currently undergoing FIPS 140-3 Level 3 certification, while also holding Common Criteria EAL4+ certification. They are trusted by organizations including SIX, the operator of Switzerland's national interbank payment system, under the oversight of the Swiss National Bank.
Who is the HSM-backed architecture built for?
Banks, payment companies, and institutional clients whose regulatory or organizational security requirements call for certified hardware in their digital asset custody infrastructure.

