Cryptocurrency & Custody Security

InfoTable of Contentsclock icon2 MIN READ·calendar iconUPDATED APR 20, 2026

Toku operates a non-custody model where clients retain full control of funds and private keys. Learn how Toku calculates payroll, proposes transactions to your custody provider, and confirms settlement - with client approval required at every step.

Last Updated: April 2026

Classification: External / Client-Facing

Contact: [email protected]


Non-Custody Model

Toku operates on a strict non-custody model. This is an architectural decision, not a policy choice. Toku never takes custody or control of client funds. Clients select their custody provider and keep full control of private keys and transaction approval.

Toku's role is to calculate payroll settlement amounts, propose transactions to the custody platform, and confirm settlement after client-approved execution. Toku does not hold funds, private keys, or signing authority at any point.


Transaction Flow

The stablecoin payment process follows a strict approval chain:

  1. Calculation: Toku calculates the stablecoin settlement amount based on payroll data from the client's HRIS and payroll platforms.
  2. Proposal: Toku proposes the transaction to the client's custody provider via authenticated API, including recipient wallet address, amount, and internal reference ID.
  3. Client Approval: The client reviews and approves the transaction through their custody provider's interface, typically using multi-signature or policy-engine approval.
  4. Execution: The custody provider executes the approved transaction on the blockchain.
  5. Confirmation: Toku confirms settlement and updates payment records with the transaction hash and timestamp. Toku cannot unilaterally execute any transaction. Client approval is enforced at the custody platform level, outside of Toku's infrastructure.

Supported Stablecoins and Assets

Toku supports commonly used stablecoins including USDC (Circle), PYUSD (PayPal), USDT (Tether), RLUSD (Ripple), and GUSD (Gemini) across multiple blockchain networks. Clients can enable specific stablecoins and networks based on their preference. Toku can accommodate virtually any network and token combination.


Custody Provider Integrations

Toku integrates with institutional-grade custody providers that maintain their own security certifications and compliance programs:

Provider Integration Type
Fireblocks API integration with IP whitelisting
Coinbase Prime API integration
Safe (Gnosis) Smart contract-based multi-sig
Squads Solana-native multi-sig
Bridge Settlement integration
Anchorage API integration

Each integration uses scoped API credentials that can propose transactions but cannot sign or execute them.


Wallet Security

Employee wallet addresses are collected through the Toku platform and stored encrypted (AES-256 at rest). Wallet addresses are used exclusively for routing stablecoin payments. Toku does not have access to employee private keys or the ability to move funds from employee wallets.


Blockchain Transaction Integrity

All completed transactions are recorded with the on-chain transaction hash, providing an immutable, independently verifiable record of every payment. Clients and employees can verify any transaction directly on the relevant blockchain explorer.


Separation of Duties

The non-custody model creates a natural separation of duties. Toku handles calculation and proposal. The client handles approval and execution through their custody provider. No single party can unilaterally move funds. This is enforced at the infrastructure level, not by policy alone.

Was this article helpful?

Can't find what you're looking for?

The Toku AI assistant has read every article. A human specialist reviews every submission.