Instructions accepted in English & German

Diese Seite ist auch auf Deutsch verfügbar.

Zur deutschen Fassung wechseln

The custody & escrow lifecycle

How Escrow Chambers holds and releases digital assets

Every mandate follows the same documented path: instruct, verify, create the vault, fund, hold, satisfy the conditions, release, report. This page sets out each stage in full — what happens, who is responsible, what evidence is produced, and what happens when something goes wrong.

Reading time · approx. 9 minutes Applies to · all escrow and custody mandates Languages · English, German Last reviewed ·

The short version

Escrow Chambers takes control of digital assets under a written mandate, holds them in a segregated vault that no single person can move, and releases them only when the conditions recorded at the outset have been evidenced and approved by the required quorum.

The design goal is narrow and deliberate: remove every point at which a single failure — a compromised inbox, a dishonest employee, a misread instruction, a lost device — could cause the wrong value to move to the wrong place. That is achieved by separating three things that most wallets combine: the ability to hold an asset, the authority to instruct a transfer, and the power to approve one.

Escrow Chambers holds. Your instructing party instructs. Your named signatories approve. None of the three can substitute for another, and the platform records the boundary between them on every action.

Stage by stage

The eight stages of a Escrow Chambers mandate

Stages one to three are onboarding and happen once. Stages four to seven repeat for each tranche of value where a mandate releases in instalments. Stage eight closes the file.

Instruct — agreeing the terms

The mandate begins with a written instruction that answers five questions: which assets are to be held, who is depositing them, who is entitled to receive them, what must happen before they may be released, and who is authorised to say that it has happened.

We work from your documentation. If the escrow sits under a share purchase agreement, a settlement agreement, a tribunal order or a restraint order, the release conditions are drafted to mirror that instrument rather than to replace it. Where the underlying agreement is silent or ambiguous on a point that matters operationally — the precise destination address, the treatment of network fees, what happens on a partial deposit — we raise it before the vault is opened rather than after it is funded.

The output of this stage is a signed escrow mandate: the single document that governs what the vault may do for the rest of its life.

Owner · Instructing party & custody desk Output · Signed escrow mandate Typical duration · 1–5 business days

Verify — identification, ownership and screening

Before any address is generated, every party to the escrow and every proposed signatory is identified and verified. For corporate parties this extends to the ownership chain and to the individuals who ultimately control the entity. For enforcement mandates it extends to confirming the officers authorised to act and the instrument under which they act.

All parties, signatories and known destination addresses are screened against sanctions lists, politically exposed person data and adverse media, and re-screened for the life of the mandate. Where digital assets are being transferred in from a known source, we assess the on-chain provenance of those assets before agreeing to accept them.

This stage is where we decline mandates. If we cannot establish who controls an asset, or the provenance analysis raises questions that cannot be answered, we say so in writing and the vault is not opened. That outcome is deliberately available to us, because a custody service that accepts everything protects nobody.

Owner · Compliance Output · Verification file, screening record, acceptance decision Typical duration · 1–10 business days

Create the vault — segregation and signatories

On acceptance, a vault is created for the matter. Vault creation generates fresh key shares using multi-party computation across separate hardware security modules; at no point does a complete private key exist on any single machine. The vault is assigned its own on-chain address — or one address per network where the mandate covers several — and that address belongs to this matter and no other.

Named signatories are enrolled with individual credentials and hardware-backed second factors. Shared logins are not permitted. The approval quorum is set at this point: two of three by default, with three of five and four of seven available where the value or the sensitivity of the matter justifies it.

Optional controls are configured now because they are difficult to add credibly later: destination allowlists, per-transaction and per-period value limits, cooling-off periods on releases, and dual-control requirements for changes to the vault's own configuration.

Owner · Custody operations Output · Vault address, signatory enrolment, control configuration Typical duration · Same business day

Fund — deposit and inbound verification

The depositing party sends the agreed assets to the vault address. We recommend, and for larger balances require, a test transfer of a small amount first: it confirms the address, the network and the token contract before value is at risk. The test amount forms part of the escrow and is not charged for separately.

Every inbound transaction is screened as it arrives. We check the sending address against sanctions and illicit-finance datasets, trace the provenance of the funds, and confirm that the asset received matches the asset the mandate describes — an important check on networks where a token symbol can be counterfeited by an unverified contract.

Assets are credited to the vault once the network-specific confirmation threshold is reached: six blocks on Bitcoin, finalisation on Ethereum, and equivalents elsewhere. Until that point the deposit shows as pending and cannot be released. If a deposit arrives that the screening flags, it is quarantined in place — it stays at the vault address, it is not credited, and it is escalated to the instructing party and to compliance the same day.

Owner · Depositing party Output · Confirmed deposit, screening result, on-chain reference Typical duration · Minutes to hours

Hold — custody and monitoring

Between funding and release, the assets simply sit. That is the point. Escrow Chambers does not lend, stake, trade or otherwise deploy the assets it holds, and it earns nothing from their movement, so there is no commercial pressure on the balance.

Balances rest in cold configuration: the key shares required to sign are held offline and are only brought into a signing ceremony when an approved release requires it. The vault address is monitored continuously for inbound deposits, unexpected outbound activity, dust and token-approval attacks, and interactions involving addresses that become sanctioned during the holding period. Anything unusual raises an alert to the named contacts on the matter and is recorded in the audit log whether or not it required action.

Authorised users can view the vault at any time through the client portal: current balance, deposit history, condition status, pending instructions and the full audit trail. Viewing rights and approval rights are separate, so counsel, clients and auditors can be given visibility without being given authority.

Owner · Custody operations Output · Continuous monitoring record, on-demand statements Typical duration · The life of the matter

Satisfy — evidencing the release conditions

When a condition is met, the party responsible for it submits the agreed evidence through the portal: a completion certificate, a sealed order, a registry extract, a signed confirmation, a transaction reference, whatever the mandate specified. The submission is timestamped, attributed to the individual who made it, and attached permanently to the condition.

The parties entitled to review that condition are notified and can approve, reject with reasons, or request further evidence. Rejections and requests are recorded as fully as approvals, so a later dispute about whether a condition was ever properly evidenced can be resolved from the file rather than from recollection.

Conditions can be sequenced, so that condition three only becomes live once conditions one and two are satisfied, and they can be tied to tranches, so that satisfying a milestone releases a defined proportion of the balance rather than the whole of it.

Owner · Parties & named approvers Output · Evidence pack, approval record per condition Typical duration · Driven by the underlying matter

Release — approval, signing and settlement

With the conditions satisfied, an authorised user raises a release instruction specifying the amount, the asset and the destination. If the vault uses a destination allowlist, only an allowlisted address can be selected; adding a new destination is itself a dual-controlled change with its own cooling-off period.

The instruction is presented to the signatories for approval. Each approval is authenticated independently, and the person who raised the instruction cannot supply the deciding approval. Where a cooling-off period applies, the release is queued visibly for its duration and any signatory may veto it during that window — the control that most reliably defeats instruction fraud, because a fraudulent release must survive scrutiny by people the fraudster does not control.

Once the quorum is reached, the transaction is constructed, signed by the distributed key shares and broadcast. The portal shows the transaction hash immediately and tracks it to the confirmation threshold. Settlement is final on-chain: there is no internal ledger entry standing in for a transfer that has not actually happened.

Owner · Signatories & custody operations Output · Signed on-chain transaction, confirmation record Typical duration · Same business day after final approval

Report and close — the evidentiary record

On completion, the matter receives a closing statement: opening position, every deposit and release with its on-chain reference, network fees, the state of every condition and the date each was satisfied, and the final disposition of the balance. It is issued as a signed PDF with a machine-readable CSV alongside it.

The full audit export is available at any time, not only at closure. It contains every logged event for the vault with timestamps, actors, IP and device attribution, and the evidence attached to each condition — the material you would need to demonstrate continuity of control to a court, a regulator, an auditor or an insurer.

Records are retained after closure for the period set in the mandate, so that the file survives the matter. Retention, deletion and the handling of personal data within the record are all specified in the mandate documentation rather than left to default.

Owner · Custody desk Output · Closing statement, signed audit export, retention schedule Typical duration · 2 business days from final release

Separation of duties

Roles and permissions

Authority in a vault is granular. Nobody holds a permission simply because of their seniority, and no role can grant itself a permission it does not already have.

Standard role model. Roles can be combined or further restricted for a specific mandate.
RoleTypically held byCan doCannot do
Instructing party The law firm, agency or practitioner that opened the mandate Raise release instructions, submit condition evidence, request statements, nominate signatories Approve its own instruction to quorum; change the release conditions unilaterally
Signatory Named partners, officers or client representatives Approve or reject instructions and condition evidence; veto during a cooling-off period Raise and single-handedly approve the same instruction; add themselves as an additional signatory
Viewer Clients, counterparties, co-counsel, auditors See balances, deposits, condition status and the audit trail Instruct, approve, or alter anything at all
Auditor External auditors, regulators, court-appointed experts Read and export the complete audit record for a defined period See unrelated matters; alter or delete any record
Custody operations Escrow Chambers Operate the signing infrastructure once a valid quorum is reached; maintain the vault Initiate a release; approve on a client's behalf; move value without the quorum
Compliance Escrow Chambers Screen parties and transactions; place a hold where law or the mandate requires it Release assets; redirect a release; approve a client instruction

The one rule behind the whole model

Escrow Chambers can always stop a release — where a sanctions match, a court order or a mandate breach requires it — and can never cause one. Every path to moving value out of a vault runs through your signatories.

Release conditions

What the escrow can be made to wait for

A condition is only useful if it is objectively testable and the evidence for it is agreed in advance. These are the forms we see most often; they can be combined, sequenced and tranched within a single mandate.

TYPE 01

Documentary

Release on delivery of a specified document: a completion certificate, a signed deed, a registry extract, a notarised confirmation, a discharge of security. The mandate names the document and who must produce it, so approval is a check rather than a judgement.

TYPE 02

Judicial or arbitral

Release on production of a sealed order, judgment or award, or on written confirmation from the tribunal or the court-appointed officer. Common in disputed asset matters where neither party should control the timing of release.

TYPE 03

Time-based

Release on a fixed date, or on the expiry of a defined period without a challenge being raised — a retention period after completion, a claims window, or a statutory notice period. Time conditions can also act as long-stop refunds.

TYPE 04

Milestone and tranche

Release a defined proportion of the balance as each milestone is evidenced. Used for staged transactions, phased distributions to creditors, and settlements payable in instalments.

TYPE 05

Third-party confirmation

Release on written confirmation from a named independent party: an expert, a surveyor, an escrow agent in another jurisdiction, or the counterparty's own counsel. The confirming party is enrolled at onboarding and authenticates individually.

TYPE 06

On-chain event

Release on a verifiable on-chain fact: a corresponding transfer reaching a specified address, a token delivery completing, or a contract state changing. Verified against the network directly rather than on a party's assertion.

Keeping conditions objectively testable

Conditions that cannot be tested objectively — “when the parties are satisfied”, “on reasonable completion” — are reworked with you at drafting stage. They do not fail safely: they fail into a dispute in which the escrow agent is asked to make a judgement it has no standing to make. If a term genuinely requires judgement, the mandate should name the person entitled to exercise it.

Under the hood

Key management, in detail

Custody failures are almost never cryptographic. They are operational: a key that existed somewhere it should not have, a backup nobody controlled, an approval process one person could satisfy alone. The architecture below is designed against those failures specifically.

No complete key, ever

Signing keys are never generated as a whole and then divided. Independent shares are generated separately inside their own hardware security modules using multi-party computation, and a signature is produced by those shares co-operating without any of them disclosing itself. There is no file, no device and no person from which a complete private key could be extracted, because one has never existed.

Geographic and organisational separation

Shares are held in separate facilities under separate physical access control, with at least one share held under a governance arrangement that is independent of day-to-day operations. Compromising a single site, a single administrator or a single jurisdiction is not sufficient to move value.

Signing requires your quorum first

The infrastructure will not begin a signing ceremony until the client-side approval quorum has been satisfied and independently verified. The technical capability to sign and the authority to sign are separated deliberately: Escrow Chambers operates the former and never holds the latter.

Recovery without a single point of trust

Recovery material is distributed so that reconstituting access requires the co-operation of parties who do not routinely work together, under a documented procedure that is tested on a defined cycle. The procedure is designed to work in the event that Escrow Chambers ceases to operate, and its existence does not create a shortcut around the normal approval quorum.

Addresses are verified, not assumed

Vault addresses are derived and independently re-derived on separate systems before they are published to a client, and destination addresses are checksummed, network-checked and confirmed out of band before a first release. Address substitution is one of the most common and most expensive attacks in this sector, and it is countered procedurally rather than by care alone.

Everything is logged, nothing is editable

The audit log is append-only at the storage layer. Events can be added; they cannot be amended or removed, including by Escrow Chambers administrators. Log integrity is verifiable independently, so the record's value does not rest on trusting the party that produced it.

Exception handling

How exceptions are handled

A custody service is judged on how it handles the unexpected. Each scenario below has a documented path, agreed before it is ever needed.

Standard exception paths
ScenarioWhat Escrow Chambers does
The parties dispute whether a condition is met The vault holds. Escrow Chambers does not adjudicate: the assets remain in escrow until the parties agree in the form the mandate requires, or until a court or tribunal with jurisdiction directs otherwise. Every submission, approval and rejection is available to both parties and to any tribunal.
A signatory becomes unavailable Signatories can be replaced under the substitution procedure recorded in the mandate — typically requiring the remaining quorum plus the instructing party. This is why quorums are set with redundancy: a 2-of-3 vault survives losing one signatory without the assets becoming unreachable.
An instruction looks irregular Releases that deviate from the established pattern — a new destination, an unusual amount, an out-of-hours request, a change of contact details immediately before an instruction — are held and verified out of band with a known contact on a previously recorded channel, never on the details supplied in the instruction itself.
Sanctioned or tainted value arrives The deposit is quarantined at the vault address, is not credited to the available balance, and cannot be released. Compliance escalates the same day, reports where legally required, and the assets are dealt with in accordance with the applicable regime and any direction received from the competent authority.
A court order requires a hold or a transfer Orders from a court of competent jurisdiction are actioned, and the affected parties are notified to the extent the order permits. Every step taken in response is logged, so the response itself is auditable.
A party sends the wrong asset or the wrong amount Unexpected inbound value is identified on arrival and is not credited to the mandate. It is reported to the instructing party, and returned to a verified originating address where that can be established safely, following the same approval controls as any other release.
A network becomes congested or unstable Releases are broadcast with fee strategies appropriate to the network's conditions and monitored to confirmation, with replacement where a network permits it. Where a chain's reliability degrades materially, releases on that chain are paused and the position is reported rather than settled optimistically.
Escrow Chambers ceases to operate Client assets are segregated and are not part of the operating estate. The documented recovery procedure enables the entitled parties to regain control of the assets independently of the continued existence of the business.

Service levels

Timelines you can plan around

Escrow timing is usually driven by the underlying matter rather than by the custodian, but the parts we control are committed in the mandate. The figures below are the standard positions; urgent enforcement and time-critical completions can be escalated.

Durations are business days unless stated otherwise and run from receipt of complete information.

Standard service levels
ActivityStandard
Acknowledgement of a new enquirySame day
Onboarding decision after complete documents2–3 days
Vault creation after acceptanceSame day
Deposit credited after confirmationsImmediate
Release broadcast after final approvalWithin 4 hours
Statement or audit export on request1 day
Closing statement after final release2 days
Security incident notificationWithout undue delay

Commercials

How the service is charged

Fees are agreed in the mandate before a vault is opened and are quoted as a fixed schedule, not as a percentage of movement. We do not earn from the assets we hold, we do not take a spread on conversion, and we do not receive anything from a release that we would not receive from a refund — so nothing in our commercial model gives us a preference about where the value ends up.

  • Mandate fee — a one-off charge covering onboarding, verification, drafting review and vault creation.
  • Custody fee — a periodic charge for holding, monitoring and reporting, based on the number of vaults and the reporting requirement rather than on the balance held.
  • Transaction fee — a fixed charge per release, plus the actual network fee at cost, shown separately on every statement.
  • Additional services — expert statements, bespoke reporting formats, additional signatory enrolment or out-of-hours escalation, quoted in advance.

Who pays

The mandate specifies which party bears each fee, and whether fees may be deducted from the escrowed balance or must be settled separately. Where fees are deductible, the deduction is itself subject to the approval quorum and appears in the audit trail like any other movement.

No surprises at release

Network fees are shown as an estimate when a release is raised and as an actual figure once the transaction confirms. A release will never quietly settle for less than the instructed amount because a fee was taken from it without being specified.

Working with your systems

Reporting and integration

Most clients work entirely in the portal. Where a firm or an agency needs the custody record inside its own case management, practice management or evidence system, the position can be pushed rather than re-keyed.

  • Scheduled statements delivered to named recipients as signed PDF and CSV on a daily, weekly, monthly or matter-close basis.
  • Machine-readable exports of balances, movements, condition status and audit events for ingestion into practice or case management systems.
  • Read-only access for auditors and court-appointed experts, scoped to a specific matter and a specific period.
  • Event notifications on deposit, approval, release and exception, delivered to named contacts through channels agreed at onboarding.

What a statement contains

Matter reference
Your reference and the vault identifier
Position
Opening and closing balance per asset, per network
Movements
Every deposit and release with transaction hash, block and timestamp
Conditions
Status of each condition and the date it was satisfied
Approvals
Who approved what, when, and from where
Fees
Service fees and actual network fees, separately identified
Integrity
Digital signature over the statement contents

Next

The questions counsel ask most

The FAQ answers the questions that come up most often on first mandates — legal treatment, what happens on insolvency, which assets we hold, how access is controlled and what the record actually looks like.

Open a mandate

Tell us the matter type, the assets involved and the release conditions you need. We will confirm in writing whether we can hold it, on what terms, and how long onboarding will take.