Skip to content
Shivacha — Simplifying Tech Solutions
Shivacha Digital AssetsInstitutional Digital Asset Infrastructure

Transaction Policy Engine

Policy engines that govern every digital asset transaction — rules, limits, quorums, allowlists and screening checks.

Production · multi-region
Illustrative

Region Aactive

Load balancer · WAF
api web worker
Postgres primary Object storage

Region Bstandby

Load balancer · WAF
api web worker
Postgres replica Object storage

Async replication · automated failover · backups tested

Observability

MetricsLogsTracesSLO alerts

Security

IAMSecretsPrivate networkIaC

Overview

A transaction policy engine sits between transaction requests and signing, enforcing your rules automatically: who can initiate, who must approve, which destinations are allowed, amount and velocity limits, time windows and screening results. We build policy engines with a clear rules language, versioning, simulation and audit — integrated with custody and wallet systems.

Shivacha provides technology and integration services. Custody, compliance and regulated activities are performed by your organisation or licensed partners.

Common use cases

  • Institutional withdrawalsControlled client and treasury withdrawals.
  • Exchange hot wallet controlLimits on hot wallet exposure.
  • DAO and fund treasuryGovernance-aligned spending rules.
  • Payment operationsRules for high-volume payments.

Quick answers

Transaction Policy Engine at a glance

The essentials in brief. Every project is scoped individually — ask us for specifics.

What is transaction policy engine?
Policy engines that govern every digital asset transaction — rules, limits, quorums, allowlists and screening checks.
Who is it for?
Typically exchange operators, brokers, fintechs and Web3 companies launching trading, wallet, custody or on/off-ramp products.
What does Shivacha provide?
  • Rules language
  • Quorum approvals
  • Allowlists
  • Limits
  • Screening integration
  • Policy simulation
Which technologies are used?
MPC Cryptography, HashiCorp Vault, Ethereum, Solana, Go (Golang), PostgreSQL — chosen to fit your stack and constraints.
How does the process work?
Operating model → Custody integration → Policy & workflow → Compliance integrations → Reporting & reconciliation.
What affects the cost?
  • White-label configuration vs custom modules
  • Number of assets, chains and trading pairs
  • Custody model and provider
  • Liquidity, fiat on/off-ramp and KYC integrations
  • Mobile apps and admin scope
  • Security testing and operational requirements
How long does it take?
White-label implementations typically take 2–5 weeks of software work depending on product and customisation; advanced custom platforms 4–8+ weeks. Licensing, banking, custody and liquidity partner onboarding run on their own timelines.
How do I get started?
Share a short brief in the form below, book a 30-minute call or message us on WhatsApp. A senior engineer replies within one business day; NDA on request.

Capabilities

What we deliver

Rules language

Readable, versioned policy definitions.

Quorum approvals

Role-based approval thresholds.

Allowlists

Pre-approved destinations.

Limits

Amount, velocity and time-based limits.

Screening integration

Risk scores as policy inputs.

Policy simulation

Test changes before deployment.

Architecture

Engineered right from day one

The layers we typically design for institutional digital asset infrastructure, adapted to your stack and partners.

  • Integration, not custodyWe integrate with custodians; we do not hold client assets or keys.
  • Defence in depthPolicies enforced at application and key-management levels.
  • Audit trailsEvery request, approval and signature logged immutably.
  • Provider neutralityAdapters allow multiple custodians and compliance vendors.
Institutional Digital Asset Infrastructure · reference architecture
5Operations console
ApprovalsTreasuryReportingAudit
4Policy engine
Transaction rulesQuorumsLimitsWhitelists
3Custody & keys
Qualified custodian APIsMPCHSMMultisig
2Compliance integrations
Blockchain analyticsTravel ruleTransaction monitoring
1Chains & venues
NetworksExchangesOTC desksStaking providers

Delivery

How an engagement runs

  1. 1

    Operating model

    Roles, approval policies, asset coverage and existing controls.

  2. 2

    Custody integration

    Connection to qualified custodians and key-management providers.

  3. 3

    Policy & workflow

    Transaction policies, approval quorums and segregation of duties.

  4. 4

    Compliance integrations

    Screening, monitoring and travel-rule providers integrated into flows.

  5. 5

    Reporting & reconciliation

    Books-and-records, accounting exports and daily reconciliation.

Security

Security built into delivery

Controls we apply by default on this kind of work — not a separate phase at the end.

Wallet segregation

Hot/cold tiers, withdrawal limits and approval quorums.

Custody integration

MPC, multisig or HSM-backed providers — keys never in application code.

Ledger reconciliation

Internal balances reconciled against on-chain and partner records.

Admin controls

Role-based access, maker-checker approvals and full audit trails.

Dedicated team

Blockchain Engineering Team

Engineers for protocols, nodes, indexing, custody integration and tokenization platforms.

FAQ

Frequently asked questions

Can policies be changed without code?

Yes, through a governed policy console with its own approval workflow.

Where are policies enforced?

At the application layer and, where supported, within key management systems for defence in depth.

Can you connect our existing systems to a custodian?

Yes. We integrate custodian and MPC provider APIs with your treasury, accounting, trading and reporting systems, including approval workflows.

Do you provide transaction monitoring or travel-rule services?

No — we integrate with specialist providers of blockchain analytics, transaction monitoring and travel-rule messaging, and build the workflows around them.

Next step

Discuss Your Launch.

Tell us about your transaction policy engine requirements — goals, timeline and constraints. We will reply with questions, an approach and next steps.

  • Senior engineer reads every enquiry
  • Reply within one business day
  • NDA on request

Prefer to talk first?

Book a 30-minute call, or message the nearest team on WhatsApp.

Book a Call

Your details are used only to reply to this enquiry.

Step 1 of 2Your details

Confidential. We reply within one business day. Privacy