In our conversations with banks and financial institutions, we consistently discuss regulatory compliance, data residency, business continuity, and operational resilience.
Questions go beyond the European regulatory framework, covering signing authority and asset control across jurisdictions; including what would happen if a US regulatory or sanctions action were ever directed at Fireblocks, Inc in the United States. What follows draws directly on the due diligence materials Fireblocks has prepared for European financial institutions.
Data residency is often the first question we get asked. The Fireblocks EU SaaS environment is deployed exclusively within the EU, across data centres located in four separate European countries. Which means that a failure at any single centre doesn’t disrupt the platform. Limited data may also be processed in the US as part of global support operations, subject to Standard Contractual Clauses and the other safeguards required under EU data protection law. Beyond data residency, several other factors, technical architecture, operational continuity, and contractual structure, reinforce this independence, and each is addressed in turn below.
Technical Architecture: Key Control and Signing Authority
Customers operating with Fireblocks MPC are the sole signing authorities for digital asset transactions. The critical private key share is generated, stored, and used exclusively within the customer’s own hardware boundary. No key material ever leaves this environment. At no point does Fireblocks hold, generate, or have access to full private key material. As a result, Fireblocks has no technical capability to initiate, authorise, redirect, or tamper with any customer transaction.
For clients that prefer a hardware security module (HSM) based deployment, the client operates its own HSM infrastructure as the sole signing authority for digital asset transactions. Private keys are generated, stored, and used exclusively within the client’s own hardware boundary; no key material ever leaves the client’s HSM environment. The practical consequence is the same. Fireblocks has no technical capability to initiate, authorise, redirect, or tamper with any transaction on the client’s digital assets.
This holds under all circumstances. Transaction authorisation policies are configured within the Fireblocks Policy Engine and enforced within hardware enclaves. They cannot be modified without the client’s own designated admin quorum performing hardware-to-hardware multi-factor authentication, and a suspension of the Fireblocks SaaS platform would not alter or compromise these policies. Wallet addresses and onchain balances are recorded on the relevant blockchain and are not held or controlled by Fireblocks under any deployment model. No action directed at Fireblocks, whether operational, regulatory, or legal, can give Fireblocks unilateral control over a client’s private keys or digital assets. This is a function of the underlying cryptographic architecture.
Clients can also act independently of Fireblocks at any time. Every Fireblocks customer holds a reconstructable copy of the complete private key from onboarding onward, which enables them to maintain access to their digital assets independently of the Fireblocks platform and to migrate assets to external platforms whenever they choose. Control over a client’s digital assets does not depend on Fireblocks’ continued operation or cooperation.
Business Continuity and Operational Resilience
Fireblocks maintains a formal Business Continuity Plan (BCP) and Disaster Recovery (DR) programme certified under ISO 22301, covering technological, human, and geographical risk scenarios. The programme is reviewed annually by the CISO, CTO, and IT Manager, with updates triggered by material changes to business processes, infrastructure, or risk profile.
The programme is independently validated through Fireblocks’ annual SOC 1 Type 2 audit (Control Objective 8: Backup and restoration controls, no exceptions noted). Technical database restoration testing was performed during 2025 and confirmed successful recovery.
Fireblocks employs around 900 professionals globally across three operational hubs, operating a follow-the-sun customer support model. Engineering and R&D operations are performable remotely. There is no single geographic disruption that affects overall platform operations.
Exit, Migration, and Service Suspension
Exit assistance and transition support for Fireblocks customers are detailed within the Master Service Agreement (MSA), including provisions relating to off-boarding support.
In addition, for clients operating under EU financial services regulation, contractual protections are reinforced through a dedicated regulatory addendum. Fireblocks supports our regulated customers on their MiCA, DORA and MiFID obligations.
After contract termination, Fireblocks runs a structured workspace disabling process. As part of this process, users with signing capabilities are disabled.
For legal and reconciliation purposes, customer data is securely retained for 7 years following contract termination. Upon request at contract termination, and within applicable legal guidelines, Fireblocks can consider data purge requests on a case-by-case basis.
Conclusion
Fireblocks supports many regulated entities running in production across major financial centers in the EU and EEA on their digital asset operations. Our technical architecture, operational resilience, data residency, and contractual structure are built to serve banks and financial market infrastructures operating under European regulatory requirements. A regulatory action directed at Fireblocks, Inc. in the US does not, as a matter of technical fact, give Fireblocks any greater ability to access, freeze, or redirect a client’s digital assets.
If you would like to discuss your specific institution’s questions, reach out here to set up a meeting or meet with me and my colleagues at Sibos Miami this year.
NOTE: This blog is not legal advice. Financial institutions should seek independent legal counsel in relation to their specific regulatory obligations.