Behind most banks and fintechs today that have anything to do with crypto, there is specialised infrastructure protecting keys, wallets, and overall digital asset security. Joining me is Jose Aguinaga, VP of Solutions Engineering at DFNS. Jose, welcome to the show. What does DFNS do and what problem in digital asset markets are you solving?
Thank you, Lucy. DFNS is building the core banking platform for digital assets. We are a provider not only of digital asset infrastructure for wallets and capabilities, but also multiple policies, treasury management, and all sorts of solutions for regulated institutions and other players who want to enter the virtual asset space.
You call yourself a core banking platform for digital assets — that is quite a bold claim. How does it actually work inside a bank or fintech?
We recently changed the name from wallet management infrastructure to core banking platform, because that is genuinely what we do. We provide services that go end to end for a financial institution — settlement, exchange capabilities, and all sorts of digital asset operations that go far beyond just signing and broadcasting transactions, which is what a key management provider does. We go far beyond wallet infrastructure — we provide policies, integrations with KYC providers, and the full operating layer. We serve more than 100 institutions across the world — financial institutions, digital asset providers in many markets — that leverage our capabilities to then provide services in the digital asset ecosystem.
For banks not yet in digital assets and thinking about how to integrate this new asset class, are you the first people they call?
Yes — and we are very lucky to be in that position. Custody is one of the first layers of solutions that institutions look to cover. When a financial institution wants to enter the ecosystem, they immediately face the challenge of providing wallet capabilities to their end users. We are in a unique position to offer not only the layer that enables them to access blockchains and the underlying instruments, but also the framework they can use to then provision more exciting services — tokenisation, tokenised money market funds, digital securities, and more.
Everyone in crypto talks about MPC key management. Can you explain what it actually is and why institutions need it?
MPC stands for multi-party computation. It has been in the cryptographic industry for many years, but what makes it extremely interesting is that it allows you to segregate risk across multiple entities. At DFNS, our capabilities allow you to distribute cryptographic materials across multiple entities. What makes us unique is that we allow institutions to access these cryptographic materials in their own infrastructure without relying on black boxes they have to trust. We are among the very few providers that have our own MPC algorithm — QQ25, developed by cryptographers Jonathan Katz and Antoine Orban. It is a public white paper that anyone can inspect and research. We rely on this algorithm to deliver top-tier, millisecond-grade capabilities.
How does DFNS help clients navigate different regulatory environments across multiple jurisdictions?
We build our solution to match multiple rulebooks across the world. We have served clients in regulated industries across virtually every jurisdiction at this point. What works in Japan may not work in the UAE. We have built a flexible deployment model — some jurisdictions are satisfied with distributing cryptographic material across entities, while others prefer having all cryptographic material on their own on-premises infrastructure. We have built solutions to cater to each different jurisdiction. Right now we have clients in the UAE, clients across Asia, and we are seeing strong success in North America as well.
The UAE specifically — you are ADGM-based. What is unique about building here?
We are extremely happy to operate in this region. We serve clients that have successfully obtained licenses from both VARA and the ADGM FSRA — which means we have certified that our services satisfy not only security requirements, but third-party risk management, cybersecurity threat models, and all sorts of high-level supervisory requirements. If you can certify that you have clients that have used your solution and passed those regulators' requirements, it gives you a real moat. We have to provide a good amount of evidence — audits, penetration tests, up-to-date certifications. That is something very unique to the UAE. We get inbound and outbound from this region, and more importantly, we get the reputation of being able to sustain the challenges from top-tier jurisdictions and top-tier regulators.
What are the top questions potential clients come to you with?
Institutions want to understand the cryptographic model behind the service. When we mention MPC, they do not just want to know that cryptographic primitives are distributed — they want to know in which devices those shares are stored, who can access them, what the security models are. We believe in transparency — a vendor should be very precise and say: your material is based in this data centre, in this format, encrypted by this key. If you are running an RFP or RFI process, it is critical to make sure your vendor of choice can answer those questions clearly.
Jose, that has been fascinating. Security is absolutely top of mind for anyone in crypto. Thank you so much for joining us.
Thank you so much for having me, Lucy. I appreciate the invitation.