MPC vs HSM custody, explained simply

When businesses compare digital-asset custody solutions, they often encounter two terms: MPC and HSM. Both technologies are designed to protect the private keys used to move digital assets, but they work in different ways.

MPC, or multi-party computation, divides control of a private key between several parties. No single party holds enough information to sign a transaction alone. When a transaction is approved, the parties work together to create the signature without rebuilding the complete key.

An HSM, or hardware security module, takes a different approach. It protects the private key inside dedicated hardware built for cryptographic operations. The key is created and used within this protected environment and does not need to be exposed during signing.

MPC distributes cryptographic responsibility. An HSM creates a protected place for cryptographic operations. Both can form part of a secure custody model.

Security depends on more than the technology

It is tempting to think that MPC removes every single point of failure or that an HSM places all control in one device. In reality, the wider design determines how secure a custody solution is.

An MPC system still needs rules governing who controls each key share, how those people are authenticated and what happens when one of them becomes unavailable. If the same provider operates every party, the technology may be distributed while responsibility remains concentrated.

An HSM system can also distribute responsibility. Access to the hardware can depend on several approvals, customer-held encryption keys and business policies. HSMs can be deployed with backup and recovery arrangements rather than relying on one physical device.

The important issue is therefore not simply whether a custody platform uses MPC or HSM technology. It is whether one person or provider can move funds alone, whether company policies are enforced before signing and whether the business can recover its assets if something goes wrong.

Why Fortris uses HSM technology

Fortris uses IBM Hardware Security Modules as the protected foundation for key generation and transaction signing. HSMs have been used for decades in banking, payments and government systems, with recognised standards governing how cryptographic modules are designed and tested.

The HSM, however, is only one part of the Fortris custody model.

Before a transaction can be signed, it must pass through the company’s approval process. The Fortris governance service checks the rules attached to the account, such as how many approvals are required or whether a transaction falls within an agreed amount limit.

Approvals are connected to verified users and FIDO2 devices. This keeps the process inside the platform instead of relying on instructions sent through email, Slack or messaging apps. Each action remains connected to the person, device and policy involved.

Once every condition has been met, the HSM produces the technical signature and the transaction can be sent to the blockchain. Human approval and cryptographic signing remain separate, but they operate as parts of the same controlled process.

Fortris manages the infrastructure; the customer controls the funds

The defining feature of the Fortris model is not the HSM on its own. It is the way control is divided between Fortris and the customer.

Fortris provides and manages the signing infrastructure, governance service and transaction records. The customer decides who can access accounts, who can approve transactions and which policies must be satisfied before funds move.

The customer also controls key material held in its own key management service. Fortris cannot use, extract or replace that material. This means Fortris cannot independently initiate, approve or complete a movement of customer funds.

Recovery follows the same principle. Customers receive encrypted recovery material and retain their own Recovery Key, giving them a route to regain access without depending entirely on the Fortris platform.

The architecture matters more than the acronym

MPC and HSM should not be treated as competing labels that determine whether a custody solution is secure. Both can provide strong protection when used within a well-designed operating model.

For a business, the clearest test is to establish who can move the funds, which controls must be satisfied, where the signing takes place and whether recovery remains possible if the provider is unavailable.

Fortris uses certified HSM infrastructure to protect private keys and signing. It surrounds that infrastructure with customer-controlled keys, verified approvals, enforced business policies and independent recovery.

The result is a custody model in which Fortris runs the infrastructure while the customer retains authority over every movement of funds.

Learn more about Fortris customer-controlled custody.

Fortris handles digital asset treasury operations for enterprise business.

Want to learn more? Book a demo today.