Custody Model
How the platform handles — and does not handle — investor assets
1. Purpose
This document describes how Yieldz's platform handles custody of investor assets — what the platform can and cannot do with a user's funds and securities, and why. It is written to be read alongside the Flow of Funds and Investment Transaction Flow documents, which show the same model as diagrams.
2. Summary Position
Yieldz does not hold, control, or have independent access to investor funds or securities.
Every wallet on the platform is self-custodial. Investment payments settle directly between the investor and the organization issuing the security. The platform is a facilitator of the connection between the two parties — it verifies eligibility, hosts the offering, and enforces platform-wide compliance rules — but it does not sit in the flow of funds and does not act as custodian of record for any investor's assets.
3. Wallet Architecture
Each investor wallet is secured using a two-party key structure. One key share is generated on, and remains on, the investor's own device. The second key share is generated and held by the platform's key management service. Both shares are required to authorize any transaction — neither party can act unilaterally.
This has two consequences that define the custody model:
- The investor cannot be locked out by the platform. A transaction always requires the investor's own key share; the platform cannot construct a valid signature without it.
- The platform cannot move investor assets unilaterally. The platform's key share alone cannot authorize a transaction. The platform's role is limited to countersigning a transaction the investor has already initiated and authorized, and to enforcing any configured approval policy (for example, a multi-party approval threshold on a shared wallet) before it will countersign.
The platform's countersigning role is a control function, not a custody function — it determines whether a transaction is permitted to proceed under configured policy. It does not give the platform independent authority to initiate, redirect, or withhold a user's assets outside of that role.
4. Investment Settlement
When an investor purchases a security offered on the platform, payment is transmitted directly from the investor's wallet to the issuing organization's wallet in a single on-chain transaction. The platform's transaction fee, where applicable, is transmitted in the same transaction directly to a platform-controlled address. At no point does investor principal pass through, or rest in, an account or wallet controlled by the platform.
This is illustrated in the Flow of Funds document.
5. Redemption
Where an organization elects to offer a redemption (sell-back) facility, redemption proceeds are paid from a pool funded and controlled by that organization, directly to the investor. The platform does not fund, hold, or disburse redemption proceeds. Redemption is discretionary on the part of the organization and is not guaranteed.
6. The One Narrow Exception
Court-ordered seizure. Where the platform is presented with a valid legal order requiring the seizure of a specific holder's tokens, the platform (or the relevant organization) may execute a forced transfer of the affected tokens to a designated address as part of complying with that order. Any tokens transferred this way are held only transiently, are never commingled with other assets, and exist solely for the purpose of complying with the order in question. This is a compliance mechanism operating under legal compulsion, not a custody service offered to users, and it does not apply to any transaction in the ordinary course.
7. What the Platform Does Not Do
- Does not hold investor funds in a pooled or omnibus account
- Does not hold investor securities in a platform-controlled account
- Does not have unilateral authority to move investor assets
- Is not an intermediary in the settlement of any investment transaction
- Does not act as a broker-dealer, transfer agent, or custodian in the traditional sense described by those terms
8. Regulatory Characterization
Yieldz does not act as a custodian or a money transmitter. This position follows directly from the architecture described throughout this document: the platform never holds investor funds or securities, and its only role in any transaction is to countersign under a policy that also requires the investor's own key share. The platform is never in a position to unilaterally move, withhold, or redirect an investor's assets.
