Custody built for regulated counterparties.
When a bank, fund or listed company touches digital assets, custody is the first question compliance asks. GCI is the answer — segregated, policy-controlled and audit-ready.
Speak to our institutional teamRegulated institutions need regulated custody.
Offshore wallets and self-managed keys don't survive a Malaysian compliance review. GCI gives your digital asset holdings the same custody discipline your other assets already have — under a custodian the regulator recognises. It's built for larger AUM and deep integration: custody that plugs into your own systems, with white-label options where your brand needs to lead.
Regulated & segregated
Your assets sit in segregated, policy-controlled accounts — ring-fenced from ours and from other clients', with transaction rules you define.
Governance & approvals
Segregation of duties, multi-party approval workflows and distinct Controller & Responsible Person functions — governance regulators recognise.
Institutional operations
Compliance-first onboarding, continuous monitoring, and automated statements on holdings, transactions and portfolio activity.
When institutions come to us.
Your bank is piloting a digital asset product
Before the pilot leaves the sandbox, risk will ask who holds the assets. A registered custodian behind the pilot answers the question before it's raised.
Your fund is adding digital asset exposure
LPs and auditors expect segregated custody and independent statements — not an exchange login. GCI ring-fences holdings and reports on them continuously.
You're issuing a token or a real-world asset programme
Investors want issuance proceeds and underlying assets under policy-controlled custody — with approvals and audit trails they can inspect.
Your listed company holds digital assets on the balance sheet
The board needs governance it recognises: approval quorums, segregation of duties and statements your auditors accept.
From onboarding to audit-ready custody.
- Onboard & KYCCompliance-first onboarding built for regulated entities and their documentation requirements.
- Segregate assetsYour holdings move into segregated, policy-controlled custody accounts.
- Define your policySigners, limits, whitelists and approval quorums — encoded, not promised.
- Custody & reportContinuous custody with audit-ready reporting for your auditors and board.
Policies are your first line of defence.
Custody failures are usually governance failures. GCI encodes your governance as enforceable policy: no transaction moves on one pair of hands, no role holds conflicting duties, and every action leaves an audit trail.
- Approval quorums — transactions require the signers and limits your policy defines.
- Segregation of duties — distinct Controller and Responsible Person functions, kept separate by design.
- Audit-ready reporting — automated statements your auditors can rely on, not spreadsheets.
The full security architecture — MPC, cold storage and the C.H.A.I.N. framework — is documented on our security page.
Watch a transaction earn its approvals.
Your policy decides the signers and the quorum — the platform enforces it on every transaction, with a full audit trail.
A transaction is initiated by one team member, requires a configurable quorum of approvers — two of three in this example — and only then executes into custody. No transaction moves on one pair of hands.
What the custody workspace ships with.
GCI runs on the same custody platform — every control below comes standard, with bespoke integration, white-labelling and segregated arrangements layered on top.
Multi-factor authentication (MFA)
An additional layer of authentication protecting every account beyond passwords.
Role-based access control (RBAC)
Wallet operations and permissions scoped to each user's role and responsibilities.
IP address whitelisting
Platform and API access restricted to approved IP addresses only.
Transaction quorum approval
Configurable multi-approver authorisation before high-value or sensitive transactions execute.
Every control above runs on the same MPC + cold-storage rails — see the full security architecture.
Questions we hear a lot.
How are our assets segregated from GamBit's own assets?
Client assets are held in segregated custody accounts, ring-fenced from GamBit Custody's balance sheet, with policy controls defined per client. Segregation structure and legal arrangements are documented during onboarding.
How is GCI different from your enterprise platform (GCE)?
Integration and scale. GCE is our standard custody platform, and any business can run on it. GCI is built for larger AUM and for institutions that need custody integrated deep into their own systems — with white-labelling and bespoke arrangements where needed. Both run on the same MPC rails, top-tier security and Malaysian regulatory reporting.
Which digital assets do you support?
Major digital assets including Bitcoin and Ethereum, with the supported-asset list reviewed as client demand and regulatory clarity evolve. Tell us what you hold and we will confirm coverage during scoping.
How long does onboarding take?
It depends on your entity type and documentation readiness — institutional onboarding is typically measured in weeks, not months. We will give you a concrete timeline after the first scoping call.
What reporting do we receive?
Automated statements covering holdings, transaction history and portfolio activity, designed to slot into audit and board-reporting cycles.
What is your regulatory standing?
Gambit Custody Sdn. Bhd. is regulated by Securities Commission Malaysia as a Registered Digital Asset Custodian (DAC) under the SC's Guidelines on Digital Assets — one of a small number of custodians on the SC's public Digital Assets register, where you can verify our listing. Full particulars are on our About page.
Ready to bring your digital assets under regulated custody?
Our institutional team responds within one business day.
Speak to our institutional team