Connector · Hardware-backed custody platform

Ledger Enterprise, guarding your keys.

How our Custody & wallets module uses Ledger Enterprise to keep keys in hardware and enforce approvals: how a withdrawal travels through its governance, and how we get you live.

Ledger EnterpriseHardware-backed custody platform
Website
enterprise.ledger.com
Modules
Custody & wallets
Contract
We help you get it

Who Ledger Enterprise is

Ledger Enterprise is the institutional platform of Ledger, the company founded in Paris in 2014 and known for its hardware wallets. It keeps keys in hardware security modules (HSMs) and puts governance around them: each account has rules that set who approves a transaction, in which order and up to which amount, and people approve on Ledger devices that show the real details of what they sign.

Banks, custodians, exchanges, asset managers and fintechs use it to hold their own assets or their customers' in self-custody, and it is SOC 2 Type 2 certified. Approvals enforced in hardware are why it is one of the custody providers our module connects to.

What it does in your platform

  • Custody & wallets

    Keeps the keys for your hot, warm and cold wallets in Ledger's HSMs, with an account and deposit address per customer created through its governance. A withdrawal reaches Ledger Enterprise only after the module's limits, screening and approvals, and is approved again under the account's rules before the HSM signs it.

How the connection works

The module acts in Ledger Enterprise as an API operator: an operator with its own key, admitted only once your administrators' quorum approves it. Ledger Enterprise reports events back by webhook.

  1. An account per customer

    The module requests a new account for the customer and chain. Once governance approves it, the account's trusted address becomes the customer's deposit address.

  2. A deposit arrives

    Webhooks report the incoming transaction as it is confirmed, and the account balance as it updates.

  3. Screened and credited

    The module screens the deposit and credits the customer, and the movement appears in the backoffice.

  4. A withdrawal request

    After your limits, screening and approvals, the module creates the transaction request in Ledger Enterprise, signed with its operator key.

  5. Rules and quorum

    The account's rules apply: the approvers they name, step by step, each step with its quorum, whether people on Ledger devices or the module's API operator.

  6. Signed and reconciled

    Once approved, the HSM signs and the transaction is broadcast. Webhooks report each step, and the module reconciles it with the chain.

Next to other providers

Ledger Enterprise is one of the custody providers the module runs on, next to the others in its group and your own MPC or HSM setup. The module's limits, screening and approvals stay the same whichever provider signs, and Ledger Enterprise's hardware-enforced rules add a second layer your administrators control.

Moving to another provider later, or to your own HSMs, means moving the funds and giving customers new deposit addresses. Your apps stay the same, and every past movement stays in your records.

When Ledger Enterprise fits best

A strong fit when

  • You want keys in HSMs and approvals signed on devices that show exactly what is being approved.
  • You hold your customers' assets in self-custody and want governance enforced in hardware as well as in the module.
  • You may want the signing HSM in your own data centre one day, with Ledger's on-premise option.

Also worth a look

  • An MPC platform such as Fireblocks or Cobo, if your team prefers key shares to HSMs.
  • A custodian that holds the keys for you, such as BitGo, if your licence or your clients ask for one.

How we get you live

  • The contract

    We help you get your Ledger Enterprise account and contract in place, with the workspace and the networks you need.

  • Rules and operators

    We set up the account rules with you, who approves, in which order and up to which amount, and register the module as an API operator for your administrators to approve.

  • The keys

    The API operator's key and credentials go into your platform's secrets and nowhere else, and the signing keys stay in the HSMs.

  • A full test run

    We run the whole flow before launch, a deposit, a withdrawal through the rules and the reconciliation, starting with small amounts.

Questions

Asked about this connector.

How do we get started with Ledger Enterprise?

Talk to us. We help you get the Ledger Enterprise contract in place, set up the account rules and the module's API operator with you, connect it to your platform and run the whole flow before launch.

Who approves a withdrawal?

First the module, under your limits, screening and approval quorum. Then Ledger Enterprise applies the account's rules, which can include people approving on Ledger devices and the module's API operator.

Can the keys stay in our own data centre?

Yes, with Ledger's on-premise option: the HSM that signs runs in your data centre, while Ledger hosts the governance layer. The module works with it the same way.

Why does a new deposit account need approval?

In Ledger Enterprise, creating an account is itself a governed request, so every address is under the same control as every withdrawal. We set up the rules for it with you.

Start your project

Tell us the idea. We'll show you the platform.

One call is enough to map your product to the modules that already exist.

  • Response in under one business day
  • NDA on request
  • No obligation
What are you building?