Air-gapped custody · Regulator-ready, in production
Banking-grade cold storage, truly air-gapped.
Keep the device holding your blockchain signing keys physically isolated. Choose a technical or a physical air gap: both designed, tested, audited, and deployed in production under the world's strictest digital asset regulations.
Regulatory-grade Built for the strictest regulatory regimes
■Air-gapped HSMs■FIPS 140-3 Level 3/4■Regulatory-grade custody■Sovereign deployment■Cross-domain solution■Hardware data diode■CMTA DACS key ceremonies■Technical & physical air gaps■Air-gapped HSMs■FIPS 140-3 Level 3/4■Regulatory-grade custody■Sovereign deployment■Cross-domain solution■Hardware data diode■CMTA DACS key ceremonies■Technical & physical air gaps
01Air-gapped custody
What is air-gapped cold storage?
Air-gapped means physically isolated: no cables, no wireless, no indirect
connection. In digital asset custody, it is the device holding the blockchain
signing keys that must be air-gapped, not merely the mechanism by which signing
requests are approved.
Cold storage refers to a custody configuration that precludes automated,
programmatic access to signing capabilities. A wallet that permits automated transfers
via API, does not employ secure hardware, lacks air-gapped components, or does not
require multiple human approvals cannot be considered cold.
Because signed transactions must eventually reach the blockchain, an air gap cannot
mean zero information transfer. It means no persistent connection via a computer network: removing standing connectivity to the signing environment fundamentally changes
the attack surface, mitigating high-impact events such as cyberattacks, insider
threats, and operational failures. In institutional digital asset custody, an
air-gapped cold storage architecture is the benchmark banks and regulators measure
against.
98%
Highest minimum share of client assets the strictest regimes require in air-gapped cold wallets
95%+
Cold storage thresholds increasingly common across G20 markets, some requiring fully domestic infrastructure
Technical and physical, both deployed in production by Taurus clients
02Interactive architecture
Two air gaps. One cold storage platform.
Taurus‑PROTECT supports a technical air gap for real-time operations and
a physical air gap for maximum isolation. Both build on the same baseline of
technical and operational controls, and both are deployed in production. Select one to explore
its architecture.
Technical air gap · Real-time · Regulator-ready
Cold storage with active network filtering
Designed to satisfy the strictest "technical air gap" requirements defined by regulators. HSMs have no direct connection to the custody infrastructure; isolation is enforced by cross-domain solution (CDS) components acting as unidirectional data diodes and deep-content filters that inspect every flow for malicious payloads and unauthorized transaction patterns.
Network connectivity
Permanent, but with physical + logical filtering
Restriction controls
Baseline controls + CDS: hardware data diode, fine-grained content filtering (origin, protocol, content type, size, time, custom rules)
Operational friction
Real-time processing, no manual operation needed
Isolation
High, enforced by technical controls in real time
Physical air gap · Highest isolation
Fully air-gapped cold storage, zero connectivity
Designed to satisfy the strictest "physical air gap" requirements defined by regulators. The HSM has zero network connectivity, ever. Data transfer is performed entirely manually via an encrypted, FIPS-certified USB device carried to a permanently offline, hardened workstation used exclusively for cold wallet operations. Software exploitation of the HSM via network-based attack vectors is eliminated.
Network connectivity
None. Ever.
Restriction controls
Manual transfer via encrypted FIPS-certified hardware token, dedicated Taurus tooling, role-based management, intermediate validation
Operational friction
Significant, delay to sign up to days, physical presence required
Isolation
Highest, full permanent air gap
03Point of difference
Why banks choose Taurus for air-gapped custody
A true air gap, where it counts
Regulators are specific: the device holding the blockchain signing keys must be air-gapped, not merely the approval tokens. Vendors that isolate only the approval devices while the signing system stays connected are not considered air-gapped by most regulators and banks. Taurus air-gaps the HSM itself.
Regulatory-grade, in production
Both air-gap architectures have been designed, tested, audited, and deployed in production by Taurus clients, in markets with the strictest cold storage requirements in the world.
Technical or physical, one platform
Choose the technical air gap for real-time operations or the physical air gap for maximum isolation. Both run on the same Taurus‑PROTECT cold storage platform, so you scale across jurisdictions without changing custody systems.
Sovereign by design
Where regulation requires it, the full custody stack, including the policy engine, transaction processing, and application, deploys domestically, on premises or in-country. Key material stays under the jurisdictional control your regulator expects.
Hardware root of trust
Key material and signing operations are performed within tamper-resistant FIPS 140-3 Level 3/4 hardware security modules, with audited key ceremonies following the CMTA Digital Assets Custody Standard.
Governance humans can't bypass
Multi-factor authentication, role-based access control, and segregation of duties gate every cold wallet operation. No single individual can initiate, approve, and broadcast a transaction unilaterally, and all access is logged and monitored.
04Due diligence
The air gap test
Not everything marketed as air-gapped custody passes regulatory scrutiny. Ask any custody
vendor these questions, and compare.
Criterion
Approval-token-only "air gap"
Taurus air-gapped custody
Is the device holding the signing keys air-gapped? The regulatory consensus: this is what must be isolated.
No, signing system stays connected
Yes, the HSM itself is isolated
Accepted as air-gapped by regulators and banks?
Not by most regulators and banks
Deployed in production under the strictest cold storage regimes
Choice of technical or physical air gap? Regimes differ; your architecture should adapt without replatforming.
Single connected architecture
Both, on the same cold storage platform
Technical air gap option with real-time processing? Data diode + content filtering, no manual steps.
Not applicable
Yes, CDS-based, regulator-ready
Full sovereign deployment? Policy engine, transaction processing, and application in-country.
Typically cloud-dependent
Yes, full stack deployable domestically
Based on the regulatory analysis in the Taurus white paper "Air-gapped Cold Storage
Architectures" (2026). "Approval-token-only" describes architectures where physically
isolated components approve transaction intents while the transaction-signing system
remains connected to a computer network.
05Regulatory benchmarks
Built for the strictest regulatory regimes
Cold storage requirements
What the strictest virtual asset regimes require
Between 95% and 98% of customer assets held in cold wallets
Cold wallets defined as air-gapped, i.e. "unconnected", technically or physically
Seeds protected by HSMs, in some jurisdictions required in-country
Insurance requirements on hot and cold wallet assets
Sovereignty & operations
Where regulation is heading
Some regimes require the entire wallet infrastructure domestic: seeds, policy engine, transaction processing, and application
Primary and secondary systems in-country, transaction approval never dependent on systems abroad
Local operations and response teams increasingly expected
Several G20 regulators have been enhancing cold storage requirements over the last 24 months
Taurus deploys air-gapped cold storage architectures in production in several regions
around the world, including markets supervised under some of the strictest virtual asset
custody frameworks, such as Hong Kong's and Türkiye's. Where a regulator defines the air
gap technically, the technical air gap answers with real-time filtered isolation; where it
demands a physical air gap, network connectivity is removed entirely.
“
Cold storage should not be viewed purely as a technical architecture, but as a strategic operating model decision. At its core, cold storage design is a trade-off between maximum security and operational responsiveness.
Gregor von Bergen Head of Payments, Cards and Digital Assets, Capco Switzerland Foreword to the Taurus white paper "Air-gapped Cold Storage Architectures"
06Answers
Air-gapped custody, explained
What is air-gapped custody?
Air-gapped custody is a digital asset custody configuration in which the device holding the blockchain signing keys is physically isolated: no cables, no wireless, no persistent connection via a computer network. Because signing data must eventually reach the blockchain, an air gap does not mean zero information transfer; it means removing persistent network connectivity to the signing environment, which fundamentally changes the attack surface.
What qualifies as cold storage?
Cold storage refers to a custody configuration that precludes automated, programmatic access to signing capabilities. A wallet that permits automated transfers via API, does not employ secure hardware, lacks air-gapped components, or does not require multiple human approvals cannot be considered cold.
Are hardware-token approval systems air-gapped?
No. Some vendors claim an air-gapped architecture because the components that approve transaction intents, typically hardware tokens or mobile devices, are physically isolated while the transaction-signing system remains connected to a network. Such systems are not considered air-gapped by most regulators and banks. The device holding the signing keys is what must be air-gapped.
What is a technical air gap?
A technical air gap isolates the HSM behind a cross-domain solution (CDS) that operates as a unidirectional data diode, preventing unsolicited inbound traffic, and as a deep-content filter inspecting all flows for malicious payloads and policy violations. Taurus designed this architecture to satisfy the strictest technical air gap requirements defined by regulators, with real-time processing and no manual operation.
Why do banks use air-gapped cold storage?
Banks use air-gapped cold storage to hold the bulk of client digital assets beyond the reach of network-based attacks. The strictest virtual asset regimes require 95 to 98% of customer assets in air-gapped cold wallets, and bank risk frameworks demand isolation of the device holding the signing keys. Taurus provides both a technical and a physical air-gapped cold storage architecture for banks, on one platform.
How long does signing take in a physical air gap?
In the physical air gap, data transfer is entirely manual: an approver exports the request bundle onto an encrypted, FIPS-certified USB device, carries it to a permanently offline workstation connected to the HSM, and returns the signed transaction the same way. End-to-end latency can reach several days depending on approver availability. The payoff: software exploitation of the HSM via network-based attack vectors is eliminated. It suits blockchains without signing-to-broadcast time limits, such as Bitcoin and Ethereum.
Which regulations require air-gapped cold storage?
The strictest virtual asset custody regimes require between 95% and 98% of customer assets in cold wallets, defined as air-gapped, technically or physically, with seeds protected by HSMs and, in some jurisdictions, the full custody infrastructure deployed domestically. Several G20 regulators have been enhancing cold storage requirements over the last 24 months.
Air-gapped custody
Full isolation. Documented operational trade-offs.
Taurus-PROTECT supports air-gapped architectures, in production under the world's most demanding digital asset regulations.
Air-gapped custody · Regulator-ready, in production
Banking-grade cold storage, truly air-gapped.
Keep the device holding your blockchain signing keys physically isolated. Choose a technical or a physical air gap: both designed, tested, audited, and deployed in production under the world's strictest digital asset regulations.
Regulatory-grade Built for the strictest regulatory regimes
■Air-gapped HSMs■FIPS 140-3 Level 3/4■Regulatory-grade custody■Sovereign deployment■Cross-domain solution■Hardware data diode■CMTA DACS key ceremonies■Technical & physical air gaps■Air-gapped HSMs■FIPS 140-3 Level 3/4■Regulatory-grade custody■Sovereign deployment■Cross-domain solution■Hardware data diode■CMTA DACS key ceremonies■Technical & physical air gaps
01Air-gapped custody
What is air-gapped cold storage?
Air-gapped means physically isolated: no cables, no wireless, no indirect
connection. In digital asset custody, it is the device holding the blockchain
signing keys that must be air-gapped, not merely the mechanism by which signing
requests are approved.
Cold storage refers to a custody configuration that precludes automated,
programmatic access to signing capabilities. A wallet that permits automated transfers
via API, does not employ secure hardware, lacks air-gapped components, or does not
require multiple human approvals cannot be considered cold.
Because signed transactions must eventually reach the blockchain, an air gap cannot
mean zero information transfer. It means no persistent connection via a computer network: removing standing connectivity to the signing environment fundamentally changes
the attack surface, mitigating high-impact events such as cyberattacks, insider
threats, and operational failures. In institutional digital asset custody, an
air-gapped cold storage architecture is the benchmark banks and regulators measure
against.
98%
Highest minimum share of client assets the strictest regimes require in air-gapped cold wallets
95%+
Cold storage thresholds increasingly common across G20 markets, some requiring fully domestic infrastructure
Technical and physical, both deployed in production by Taurus clients
02Interactive architecture
Two air gaps. One cold storage platform.
Taurus‑PROTECT supports a technical air gap for real-time operations and
a physical air gap for maximum isolation. Both build on the same baseline of
technical and operational controls, and both are deployed in production. Select one to explore
its architecture.
Technical air gap · Real-time · Regulator-ready
Cold storage with active network filtering
Designed to satisfy the strictest "technical air gap" requirements defined by regulators. HSMs have no direct connection to the custody infrastructure; isolation is enforced by cross-domain solution (CDS) components acting as unidirectional data diodes and deep-content filters that inspect every flow for malicious payloads and unauthorized transaction patterns.
Network connectivity
Permanent, but with physical + logical filtering
Restriction controls
Baseline controls + CDS: hardware data diode, fine-grained content filtering (origin, protocol, content type, size, time, custom rules)
Operational friction
Real-time processing, no manual operation needed
Isolation
High, enforced by technical controls in real time
Physical air gap · Highest isolation
Fully air-gapped cold storage, zero connectivity
Designed to satisfy the strictest "physical air gap" requirements defined by regulators. The HSM has zero network connectivity, ever. Data transfer is performed entirely manually via an encrypted, FIPS-certified USB device carried to a permanently offline, hardened workstation used exclusively for cold wallet operations. Software exploitation of the HSM via network-based attack vectors is eliminated.
Network connectivity
None. Ever.
Restriction controls
Manual transfer via encrypted FIPS-certified hardware token, dedicated Taurus tooling, role-based management, intermediate validation
Operational friction
Significant, delay to sign up to days, physical presence required
Isolation
Highest, full permanent air gap
03Point of difference
Why banks choose Taurus for air-gapped custody
A true air gap, where it counts
Regulators are specific: the device holding the blockchain signing keys must be air-gapped, not merely the approval tokens. Vendors that isolate only the approval devices while the signing system stays connected are not considered air-gapped by most regulators and banks. Taurus air-gaps the HSM itself.
Regulatory-grade, in production
Both air-gap architectures have been designed, tested, audited, and deployed in production by Taurus clients, in markets with the strictest cold storage requirements in the world.
Technical or physical, one platform
Choose the technical air gap for real-time operations or the physical air gap for maximum isolation. Both run on the same Taurus‑PROTECT cold storage platform, so you scale across jurisdictions without changing custody systems.
Sovereign by design
Where regulation requires it, the full custody stack, including the policy engine, transaction processing, and application, deploys domestically, on premises or in-country. Key material stays under the jurisdictional control your regulator expects.
Hardware root of trust
Key material and signing operations are performed within tamper-resistant FIPS 140-3 Level 3/4 hardware security modules, with audited key ceremonies following the CMTA Digital Assets Custody Standard.
Governance humans can't bypass
Multi-factor authentication, role-based access control, and segregation of duties gate every cold wallet operation. No single individual can initiate, approve, and broadcast a transaction unilaterally, and all access is logged and monitored.
04Due diligence
The air gap test
Not everything marketed as air-gapped custody passes regulatory scrutiny. Ask any custody
vendor these questions, and compare.
Criterion
Approval-token-only "air gap"
Taurus air-gapped custody
Is the device holding the signing keys air-gapped? The regulatory consensus: this is what must be isolated.
No, signing system stays connected
Yes, the HSM itself is isolated
Accepted as air-gapped by regulators and banks?
Not by most regulators and banks
Deployed in production under the strictest cold storage regimes
Choice of technical or physical air gap? Regimes differ; your architecture should adapt without replatforming.
Single connected architecture
Both, on the same cold storage platform
Technical air gap option with real-time processing? Data diode + content filtering, no manual steps.
Not applicable
Yes, CDS-based, regulator-ready
Full sovereign deployment? Policy engine, transaction processing, and application in-country.
Typically cloud-dependent
Yes, full stack deployable domestically
Based on the regulatory analysis in the Taurus white paper "Air-gapped Cold Storage
Architectures" (2026). "Approval-token-only" describes architectures where physically
isolated components approve transaction intents while the transaction-signing system
remains connected to a computer network.
05Regulatory benchmarks
Built for the strictest regulatory regimes
Cold storage requirements
What the strictest virtual asset regimes require
Between 95% and 98% of customer assets held in cold wallets
Cold wallets defined as air-gapped, i.e. "unconnected", technically or physically
Seeds protected by HSMs, in some jurisdictions required in-country
Insurance requirements on hot and cold wallet assets
Sovereignty & operations
Where regulation is heading
Some regimes require the entire wallet infrastructure domestic: seeds, policy engine, transaction processing, and application
Primary and secondary systems in-country, transaction approval never dependent on systems abroad
Local operations and response teams increasingly expected
Several G20 regulators have been enhancing cold storage requirements over the last 24 months
Taurus deploys air-gapped cold storage architectures in production in several regions
around the world, including markets supervised under some of the strictest virtual asset
custody frameworks, such as Hong Kong's and Türkiye's. Where a regulator defines the air
gap technically, the technical air gap answers with real-time filtered isolation; where it
demands a physical air gap, network connectivity is removed entirely.
“
Cold storage should not be viewed purely as a technical architecture, but as a strategic operating model decision. At its core, cold storage design is a trade-off between maximum security and operational responsiveness.
Gregor von Bergen Head of Payments, Cards and Digital Assets, Capco Switzerland Foreword to the Taurus white paper "Air-gapped Cold Storage Architectures"
06Answers
Air-gapped custody, explained
What is air-gapped custody?
Air-gapped custody is a digital asset custody configuration in which the device holding the blockchain signing keys is physically isolated: no cables, no wireless, no persistent connection via a computer network. Because signing data must eventually reach the blockchain, an air gap does not mean zero information transfer; it means removing persistent network connectivity to the signing environment, which fundamentally changes the attack surface.
What qualifies as cold storage?
Cold storage refers to a custody configuration that precludes automated, programmatic access to signing capabilities. A wallet that permits automated transfers via API, does not employ secure hardware, lacks air-gapped components, or does not require multiple human approvals cannot be considered cold.
Are hardware-token approval systems air-gapped?
No. Some vendors claim an air-gapped architecture because the components that approve transaction intents, typically hardware tokens or mobile devices, are physically isolated while the transaction-signing system remains connected to a network. Such systems are not considered air-gapped by most regulators and banks. The device holding the signing keys is what must be air-gapped.
What is a technical air gap?
A technical air gap isolates the HSM behind a cross-domain solution (CDS) that operates as a unidirectional data diode, preventing unsolicited inbound traffic, and as a deep-content filter inspecting all flows for malicious payloads and policy violations. Taurus designed this architecture to satisfy the strictest technical air gap requirements defined by regulators, with real-time processing and no manual operation.
Why do banks use air-gapped cold storage?
Banks use air-gapped cold storage to hold the bulk of client digital assets beyond the reach of network-based attacks. The strictest virtual asset regimes require 95 to 98% of customer assets in air-gapped cold wallets, and bank risk frameworks demand isolation of the device holding the signing keys. Taurus provides both a technical and a physical air-gapped cold storage architecture for banks, on one platform.
How long does signing take in a physical air gap?
In the physical air gap, data transfer is entirely manual: an approver exports the request bundle onto an encrypted, FIPS-certified USB device, carries it to a permanently offline workstation connected to the HSM, and returns the signed transaction the same way. End-to-end latency can reach several days depending on approver availability. The payoff: software exploitation of the HSM via network-based attack vectors is eliminated. It suits blockchains without signing-to-broadcast time limits, such as Bitcoin and Ethereum.
Which regulations require air-gapped cold storage?
The strictest virtual asset custody regimes require between 95% and 98% of customer assets in cold wallets, defined as air-gapped, technically or physically, with seeds protected by HSMs and, in some jurisdictions, the full custody infrastructure deployed domestically. Several G20 regulators have been enhancing cold storage requirements over the last 24 months.
Air-gapped custody
Full isolation. Documented operational trade-offs.
Taurus-PROTECT supports air-gapped architectures, in production under the world's most demanding digital asset regulations.
Air-gapped custody · Regulator-ready, in production
Banking-grade cold storage, truly air-gapped.
Keep the device holding your blockchain signing keys physically isolated. Choose a technical or a physical air gap: both designed, tested, audited, and deployed in production under the world's strictest digital asset regulations.
Regulatory-grade Built for the strictest regulatory regimes
■Air-gapped HSMs■FIPS 140-3 Level 3/4■Regulatory-grade custody■Sovereign deployment■Cross-domain solution■Hardware data diode■CMTA DACS key ceremonies■Technical & physical air gaps■Air-gapped HSMs■FIPS 140-3 Level 3/4■Regulatory-grade custody■Sovereign deployment■Cross-domain solution■Hardware data diode■CMTA DACS key ceremonies■Technical & physical air gaps
01Air-gapped custody
What is air-gapped cold storage?
Air-gapped means physically isolated: no cables, no wireless, no indirect
connection. In digital asset custody, it is the device holding the blockchain
signing keys that must be air-gapped, not merely the mechanism by which signing
requests are approved.
Cold storage refers to a custody configuration that precludes automated,
programmatic access to signing capabilities. A wallet that permits automated transfers
via API, does not employ secure hardware, lacks air-gapped components, or does not
require multiple human approvals cannot be considered cold.
Because signed transactions must eventually reach the blockchain, an air gap cannot
mean zero information transfer. It means no persistent connection via a computer network: removing standing connectivity to the signing environment fundamentally changes
the attack surface, mitigating high-impact events such as cyberattacks, insider
threats, and operational failures. In institutional digital asset custody, an
air-gapped cold storage architecture is the benchmark banks and regulators measure
against.
98%
Highest minimum share of client assets the strictest regimes require in air-gapped cold wallets
95%+
Cold storage thresholds increasingly common across G20 markets, some requiring fully domestic infrastructure
Technical and physical, both deployed in production by Taurus clients
02Interactive architecture
Two air gaps. One cold storage platform.
Taurus‑PROTECT supports a technical air gap for real-time operations and
a physical air gap for maximum isolation. Both build on the same baseline of
technical and operational controls, and both are deployed in production. Select one to explore
its architecture.
Technical air gap · Real-time · Regulator-ready
Cold storage with active network filtering
Designed to satisfy the strictest "technical air gap" requirements defined by regulators. HSMs have no direct connection to the custody infrastructure; isolation is enforced by cross-domain solution (CDS) components acting as unidirectional data diodes and deep-content filters that inspect every flow for malicious payloads and unauthorized transaction patterns.
Network connectivity
Permanent, but with physical + logical filtering
Restriction controls
Baseline controls + CDS: hardware data diode, fine-grained content filtering (origin, protocol, content type, size, time, custom rules)
Operational friction
Real-time processing, no manual operation needed
Isolation
High, enforced by technical controls in real time
Physical air gap · Highest isolation
Fully air-gapped cold storage, zero connectivity
Designed to satisfy the strictest "physical air gap" requirements defined by regulators. The HSM has zero network connectivity, ever. Data transfer is performed entirely manually via an encrypted, FIPS-certified USB device carried to a permanently offline, hardened workstation used exclusively for cold wallet operations. Software exploitation of the HSM via network-based attack vectors is eliminated.
Network connectivity
None. Ever.
Restriction controls
Manual transfer via encrypted FIPS-certified hardware token, dedicated Taurus tooling, role-based management, intermediate validation
Operational friction
Significant, delay to sign up to days, physical presence required
Isolation
Highest, full permanent air gap
03Point of difference
Why banks choose Taurus for air-gapped custody
A true air gap, where it counts
Regulators are specific: the device holding the blockchain signing keys must be air-gapped, not merely the approval tokens. Vendors that isolate only the approval devices while the signing system stays connected are not considered air-gapped by most regulators and banks. Taurus air-gaps the HSM itself.
Regulatory-grade, in production
Both air-gap architectures have been designed, tested, audited, and deployed in production by Taurus clients, in markets with the strictest cold storage requirements in the world.
Technical or physical, one platform
Choose the technical air gap for real-time operations or the physical air gap for maximum isolation. Both run on the same Taurus‑PROTECT cold storage platform, so you scale across jurisdictions without changing custody systems.
Sovereign by design
Where regulation requires it, the full custody stack, including the policy engine, transaction processing, and application, deploys domestically, on premises or in-country. Key material stays under the jurisdictional control your regulator expects.
Hardware root of trust
Key material and signing operations are performed within tamper-resistant FIPS 140-3 Level 3/4 hardware security modules, with audited key ceremonies following the CMTA Digital Assets Custody Standard.
Governance humans can't bypass
Multi-factor authentication, role-based access control, and segregation of duties gate every cold wallet operation. No single individual can initiate, approve, and broadcast a transaction unilaterally, and all access is logged and monitored.
04Due diligence
The air gap test
Not everything marketed as air-gapped custody passes regulatory scrutiny. Ask any custody
vendor these questions, and compare.
Criterion
Approval-token-only "air gap"
Taurus air-gapped custody
Is the device holding the signing keys air-gapped? The regulatory consensus: this is what must be isolated.
No, signing system stays connected
Yes, the HSM itself is isolated
Accepted as air-gapped by regulators and banks?
Not by most regulators and banks
Deployed in production under the strictest cold storage regimes
Choice of technical or physical air gap? Regimes differ; your architecture should adapt without replatforming.
Single connected architecture
Both, on the same cold storage platform
Technical air gap option with real-time processing? Data diode + content filtering, no manual steps.
Not applicable
Yes, CDS-based, regulator-ready
Full sovereign deployment? Policy engine, transaction processing, and application in-country.
Typically cloud-dependent
Yes, full stack deployable domestically
Based on the regulatory analysis in the Taurus white paper "Air-gapped Cold Storage
Architectures" (2026). "Approval-token-only" describes architectures where physically
isolated components approve transaction intents while the transaction-signing system
remains connected to a computer network.
05Regulatory benchmarks
Built for the strictest regulatory regimes
Cold storage requirements
What the strictest virtual asset regimes require
Between 95% and 98% of customer assets held in cold wallets
Cold wallets defined as air-gapped, i.e. "unconnected", technically or physically
Seeds protected by HSMs, in some jurisdictions required in-country
Insurance requirements on hot and cold wallet assets
Sovereignty & operations
Where regulation is heading
Some regimes require the entire wallet infrastructure domestic: seeds, policy engine, transaction processing, and application
Primary and secondary systems in-country, transaction approval never dependent on systems abroad
Local operations and response teams increasingly expected
Several G20 regulators have been enhancing cold storage requirements over the last 24 months
Taurus deploys air-gapped cold storage architectures in production in several regions
around the world, including markets supervised under some of the strictest virtual asset
custody frameworks, such as Hong Kong's and Türkiye's. Where a regulator defines the air
gap technically, the technical air gap answers with real-time filtered isolation; where it
demands a physical air gap, network connectivity is removed entirely.
“
Cold storage should not be viewed purely as a technical architecture, but as a strategic operating model decision. At its core, cold storage design is a trade-off between maximum security and operational responsiveness.
Gregor von Bergen Head of Payments, Cards and Digital Assets, Capco Switzerland Foreword to the Taurus white paper "Air-gapped Cold Storage Architectures"
06Answers
Air-gapped custody, explained
What is air-gapped custody?
Air-gapped custody is a digital asset custody configuration in which the device holding the blockchain signing keys is physically isolated: no cables, no wireless, no persistent connection via a computer network. Because signing data must eventually reach the blockchain, an air gap does not mean zero information transfer; it means removing persistent network connectivity to the signing environment, which fundamentally changes the attack surface.
What qualifies as cold storage?
Cold storage refers to a custody configuration that precludes automated, programmatic access to signing capabilities. A wallet that permits automated transfers via API, does not employ secure hardware, lacks air-gapped components, or does not require multiple human approvals cannot be considered cold.
Are hardware-token approval systems air-gapped?
No. Some vendors claim an air-gapped architecture because the components that approve transaction intents, typically hardware tokens or mobile devices, are physically isolated while the transaction-signing system remains connected to a network. Such systems are not considered air-gapped by most regulators and banks. The device holding the signing keys is what must be air-gapped.
What is a technical air gap?
A technical air gap isolates the HSM behind a cross-domain solution (CDS) that operates as a unidirectional data diode, preventing unsolicited inbound traffic, and as a deep-content filter inspecting all flows for malicious payloads and policy violations. Taurus designed this architecture to satisfy the strictest technical air gap requirements defined by regulators, with real-time processing and no manual operation.
Why do banks use air-gapped cold storage?
Banks use air-gapped cold storage to hold the bulk of client digital assets beyond the reach of network-based attacks. The strictest virtual asset regimes require 95 to 98% of customer assets in air-gapped cold wallets, and bank risk frameworks demand isolation of the device holding the signing keys. Taurus provides both a technical and a physical air-gapped cold storage architecture for banks, on one platform.
How long does signing take in a physical air gap?
In the physical air gap, data transfer is entirely manual: an approver exports the request bundle onto an encrypted, FIPS-certified USB device, carries it to a permanently offline workstation connected to the HSM, and returns the signed transaction the same way. End-to-end latency can reach several days depending on approver availability. The payoff: software exploitation of the HSM via network-based attack vectors is eliminated. It suits blockchains without signing-to-broadcast time limits, such as Bitcoin and Ethereum.
Which regulations require air-gapped cold storage?
The strictest virtual asset custody regimes require between 95% and 98% of customer assets in cold wallets, defined as air-gapped, technically or physically, with seeds protected by HSMs and, in some jurisdictions, the full custody infrastructure deployed domestically. Several G20 regulators have been enhancing cold storage requirements over the last 24 months.
Air-gapped custody
Full isolation. Documented operational trade-offs.
Taurus-PROTECT supports air-gapped architectures, in production under the world's most demanding digital asset regulations.
Air-gapped custody · Regulator-ready, in production
Banking-grade cold storage, truly air-gapped.
Keep the device holding your blockchain signing keys physically isolated. Choose a technical or a physical air gap: both designed, tested, audited, and deployed in production under the world's strictest digital asset regulations.
Regulatory-grade Built for the strictest regulatory regimes
■Air-gapped HSMs■FIPS 140-3 Level 3/4■Regulatory-grade custody■Sovereign deployment■Cross-domain solution■Hardware data diode■CMTA DACS key ceremonies■Technical & physical air gaps■Air-gapped HSMs■FIPS 140-3 Level 3/4■Regulatory-grade custody■Sovereign deployment■Cross-domain solution■Hardware data diode■CMTA DACS key ceremonies■Technical & physical air gaps
01Air-gapped custody
What is air-gapped cold storage?
Air-gapped means physically isolated: no cables, no wireless, no indirect
connection. In digital asset custody, it is the device holding the blockchain
signing keys that must be air-gapped, not merely the mechanism by which signing
requests are approved.
Cold storage refers to a custody configuration that precludes automated,
programmatic access to signing capabilities. A wallet that permits automated transfers
via API, does not employ secure hardware, lacks air-gapped components, or does not
require multiple human approvals cannot be considered cold.
Because signed transactions must eventually reach the blockchain, an air gap cannot
mean zero information transfer. It means no persistent connection via a computer network: removing standing connectivity to the signing environment fundamentally changes
the attack surface, mitigating high-impact events such as cyberattacks, insider
threats, and operational failures. In institutional digital asset custody, an
air-gapped cold storage architecture is the benchmark banks and regulators measure
against.
98%
Highest minimum share of client assets the strictest regimes require in air-gapped cold wallets
95%+
Cold storage thresholds increasingly common across G20 markets, some requiring fully domestic infrastructure
Technical and physical, both deployed in production by Taurus clients
02Interactive architecture
Two air gaps. One cold storage platform.
Taurus‑PROTECT supports a technical air gap for real-time operations and
a physical air gap for maximum isolation. Both build on the same baseline of
technical and operational controls, and both are deployed in production. Select one to explore
its architecture.
Technical air gap · Real-time · Regulator-ready
Cold storage with active network filtering
Designed to satisfy the strictest "technical air gap" requirements defined by regulators. HSMs have no direct connection to the custody infrastructure; isolation is enforced by cross-domain solution (CDS) components acting as unidirectional data diodes and deep-content filters that inspect every flow for malicious payloads and unauthorized transaction patterns.
Network connectivity
Permanent, but with physical + logical filtering
Restriction controls
Baseline controls + CDS: hardware data diode, fine-grained content filtering (origin, protocol, content type, size, time, custom rules)
Operational friction
Real-time processing, no manual operation needed
Isolation
High, enforced by technical controls in real time
Physical air gap · Highest isolation
Fully air-gapped cold storage, zero connectivity
Designed to satisfy the strictest "physical air gap" requirements defined by regulators. The HSM has zero network connectivity, ever. Data transfer is performed entirely manually via an encrypted, FIPS-certified USB device carried to a permanently offline, hardened workstation used exclusively for cold wallet operations. Software exploitation of the HSM via network-based attack vectors is eliminated.
Network connectivity
None. Ever.
Restriction controls
Manual transfer via encrypted FIPS-certified hardware token, dedicated Taurus tooling, role-based management, intermediate validation
Operational friction
Significant, delay to sign up to days, physical presence required
Isolation
Highest, full permanent air gap
03Point of difference
Why banks choose Taurus for air-gapped custody
A true air gap, where it counts
Regulators are specific: the device holding the blockchain signing keys must be air-gapped, not merely the approval tokens. Vendors that isolate only the approval devices while the signing system stays connected are not considered air-gapped by most regulators and banks. Taurus air-gaps the HSM itself.
Regulatory-grade, in production
Both air-gap architectures have been designed, tested, audited, and deployed in production by Taurus clients, in markets with the strictest cold storage requirements in the world.
Technical or physical, one platform
Choose the technical air gap for real-time operations or the physical air gap for maximum isolation. Both run on the same Taurus‑PROTECT cold storage platform, so you scale across jurisdictions without changing custody systems.
Sovereign by design
Where regulation requires it, the full custody stack, including the policy engine, transaction processing, and application, deploys domestically, on premises or in-country. Key material stays under the jurisdictional control your regulator expects.
Hardware root of trust
Key material and signing operations are performed within tamper-resistant FIPS 140-3 Level 3/4 hardware security modules, with audited key ceremonies following the CMTA Digital Assets Custody Standard.
Governance humans can't bypass
Multi-factor authentication, role-based access control, and segregation of duties gate every cold wallet operation. No single individual can initiate, approve, and broadcast a transaction unilaterally, and all access is logged and monitored.
04Due diligence
The air gap test
Not everything marketed as air-gapped custody passes regulatory scrutiny. Ask any custody
vendor these questions, and compare.
Criterion
Approval-token-only "air gap"
Taurus air-gapped custody
Is the device holding the signing keys air-gapped? The regulatory consensus: this is what must be isolated.
No, signing system stays connected
Yes, the HSM itself is isolated
Accepted as air-gapped by regulators and banks?
Not by most regulators and banks
Deployed in production under the strictest cold storage regimes
Choice of technical or physical air gap? Regimes differ; your architecture should adapt without replatforming.
Single connected architecture
Both, on the same cold storage platform
Technical air gap option with real-time processing? Data diode + content filtering, no manual steps.
Not applicable
Yes, CDS-based, regulator-ready
Full sovereign deployment? Policy engine, transaction processing, and application in-country.
Typically cloud-dependent
Yes, full stack deployable domestically
Based on the regulatory analysis in the Taurus white paper "Air-gapped Cold Storage
Architectures" (2026). "Approval-token-only" describes architectures where physically
isolated components approve transaction intents while the transaction-signing system
remains connected to a computer network.
05Regulatory benchmarks
Built for the strictest regulatory regimes
Cold storage requirements
What the strictest virtual asset regimes require
Between 95% and 98% of customer assets held in cold wallets
Cold wallets defined as air-gapped, i.e. "unconnected", technically or physically
Seeds protected by HSMs, in some jurisdictions required in-country
Insurance requirements on hot and cold wallet assets
Sovereignty & operations
Where regulation is heading
Some regimes require the entire wallet infrastructure domestic: seeds, policy engine, transaction processing, and application
Primary and secondary systems in-country, transaction approval never dependent on systems abroad
Local operations and response teams increasingly expected
Several G20 regulators have been enhancing cold storage requirements over the last 24 months
Taurus deploys air-gapped cold storage architectures in production in several regions
around the world, including markets supervised under some of the strictest virtual asset
custody frameworks, such as Hong Kong's and Türkiye's. Where a regulator defines the air
gap technically, the technical air gap answers with real-time filtered isolation; where it
demands a physical air gap, network connectivity is removed entirely.
“
Cold storage should not be viewed purely as a technical architecture, but as a strategic operating model decision. At its core, cold storage design is a trade-off between maximum security and operational responsiveness.
Gregor von Bergen Head of Payments, Cards and Digital Assets, Capco Switzerland Foreword to the Taurus white paper "Air-gapped Cold Storage Architectures"
06Answers
Air-gapped custody, explained
What is air-gapped custody?
Air-gapped custody is a digital asset custody configuration in which the device holding the blockchain signing keys is physically isolated: no cables, no wireless, no persistent connection via a computer network. Because signing data must eventually reach the blockchain, an air gap does not mean zero information transfer; it means removing persistent network connectivity to the signing environment, which fundamentally changes the attack surface.
What qualifies as cold storage?
Cold storage refers to a custody configuration that precludes automated, programmatic access to signing capabilities. A wallet that permits automated transfers via API, does not employ secure hardware, lacks air-gapped components, or does not require multiple human approvals cannot be considered cold.
Are hardware-token approval systems air-gapped?
No. Some vendors claim an air-gapped architecture because the components that approve transaction intents, typically hardware tokens or mobile devices, are physically isolated while the transaction-signing system remains connected to a network. Such systems are not considered air-gapped by most regulators and banks. The device holding the signing keys is what must be air-gapped.
What is a technical air gap?
A technical air gap isolates the HSM behind a cross-domain solution (CDS) that operates as a unidirectional data diode, preventing unsolicited inbound traffic, and as a deep-content filter inspecting all flows for malicious payloads and policy violations. Taurus designed this architecture to satisfy the strictest technical air gap requirements defined by regulators, with real-time processing and no manual operation.
Why do banks use air-gapped cold storage?
Banks use air-gapped cold storage to hold the bulk of client digital assets beyond the reach of network-based attacks. The strictest virtual asset regimes require 95 to 98% of customer assets in air-gapped cold wallets, and bank risk frameworks demand isolation of the device holding the signing keys. Taurus provides both a technical and a physical air-gapped cold storage architecture for banks, on one platform.
How long does signing take in a physical air gap?
In the physical air gap, data transfer is entirely manual: an approver exports the request bundle onto an encrypted, FIPS-certified USB device, carries it to a permanently offline workstation connected to the HSM, and returns the signed transaction the same way. End-to-end latency can reach several days depending on approver availability. The payoff: software exploitation of the HSM via network-based attack vectors is eliminated. It suits blockchains without signing-to-broadcast time limits, such as Bitcoin and Ethereum.
Which regulations require air-gapped cold storage?
The strictest virtual asset custody regimes require between 95% and 98% of customer assets in cold wallets, defined as air-gapped, technically or physically, with seeds protected by HSMs and, in some jurisdictions, the full custody infrastructure deployed domestically. Several G20 regulators have been enhancing cold storage requirements over the last 24 months.
Air-gapped custody
Full isolation. Documented operational trade-offs.
Taurus-PROTECT supports air-gapped architectures, in production under the world's most demanding digital asset regulations.