Vault provider due diligence: questions fintechs ask
For Fintechs & Neobanks
29 Sep 2026

Vault provider due diligence: questions fintechs ask

Ethan Luc
Written by Ethan Luc
Risk Management
Smart Contract Risk
Non-custodial
Institutional
Vaults

Before a neobank, exchange or payments company puts customer stablecoins into a vault, its risk team reviews who can move the funds, who can change the contract, how positions are priced and how money comes back out. Each of the ten areas pairs the question with what a strong answer contains and how Upshift answers it.

A fintech that launches a stablecoin Earn product is adding a new vendor to the path its customers' money takes. Its risk, compliance and product leads run due diligence (DD) on that vendor before signing, much as a bank reviews a payments processor before routing card settlement through it. US banking agencies set out that review for banks in their 2023 interagency guidance on third-party relationships: who controls the money, what can change without notice, who checks the vendor's work and what happens when something fails. A vault provider gets the same review, with smart contracts and signing keys in place of a processor's data centre and settlement accounts.

Upshift is non-custodial vault infrastructure. A depositor sends a stablecoin to a vault contract and receives a receipt (share) token, which it redeems at net asset value (NAV) under that vault's published withdrawal terms. Through Vault-as-a-Service, any vault type can launch under the partner's own brand and front end. The roles involved are mapped below and covered in more depth in who does what in an onchain vault.

Who can do what around an Upshift vault Roles map. The depositor uses the fintech front end to deposit into the vault contract and receives share tokens redeemable at NAV. The owner multisig, a Gnosis Safe, sets vault parameters and fees, appoints the operator, can pause, and can call emergencyWithdraw on vault-held assets. The ProxyAdmin multisig, typically 4 of 6 signers from the asset issuer, Upshift and the curator, approves code upgrades. The curator decides strategy offchain and acts through the operator. The operator, signing through MPC, runs daily operations and can pause. The policy engine checks every deployment against approved chains, protocols, tokens and contract functions. The multi-oracle NAV engine prices every position independently of the curator. Upshift's own frontend runs KYC and AML checks. Owner multisig Gnosis Safe sets parameters and fees, appoints operator, can pause, emergencyWithdraw (vault-held) ProxyAdmin multisig typically 4 of 6 signers: issuer, Upshift, curator approves code upgrades Depositor holds share tokens, redeems at NAV under vault terms Fintech front end partner's brand and app; Upshift's frontend runs KYC and AML Vault contract holds deposits, mints shares, runs redemptions Operator set by owner; MPC signing; daily jobs, can pause Curator decides strategy offchain; acts through operator deposits and redeems instructs parameter changes; most wait out a per-vault timelock code changes (proxy upgrades), multisig signs Policy engine checks every deployment: chain, protocol, token, contract function Multi-oracle NAV engine prices every position, independent of the curator checks every deployment prices every position Fireblocks MPC signs automated jobs; Fordefi is used where an external party co-signs. Neither signs owner functions. There is no guardian role: pause sits with the owner or the operator.

In the diagram, the depositor reaches the vault through the fintech's front end. The owner multisig holds parameter changes and the ProxyAdmin multisig holds code changes. The operator runs daily jobs on the curator's instruction, every deployment passes the policy engine, and the multi-oracle NAV engine prices the positions behind each share.

1. Custody and who can move funds

Question. Who holds the assets, which keys can move them, and can any single person or device send funds outside the vault's approved venues?

A strong answer names every role with power over the funds, the signing setup behind each one, and the limits on the most powerful function. It separates routine operations from emergency powers and shows that no single key can redirect customer money.

How Upshift answers. Vaults are non-custodial: deposits sit in the vault contract and its segregated subaccounts, and depositors hold share tokens. The owner of each vault is a Gnosis Safe multisig, and the owner sets the operator role. Automated jobs such as fee charging and NAV updates are signed through Fireblocks MPC (multi-party computation, where a key is split into shares so no single device holds it), and Fordefi is used where an external party co-signs. Operator transactions run through pre-transaction simulation and a maker-checker approval, where one person proposes and a second approves. Pause sits with the owner or the operator, and there is no separate guardian role. The owner's emergencyWithdraw function moves vault-held assets only, to an address the owner specifies, and doesn't reach funds deployed in subaccounts.

2. Contract changes

Question. What can change after launch, who approves each kind of change, and how much notice do depositors get?

A strong answer splits parameter changes (fees, caps, whitelists) from code changes (the contract logic itself) and gives the approval threshold and waiting period for each, including the changes that take effect immediately.

How Upshift answers. Each vault has a configurable timelock on parameter changes, so a change such as a new management fee is scheduled and waits out the delay before it applies. Not every fee change is timelocked: instant-redemption and withdrawal fees can change without that wait. Code changes are proxy upgrades, used for things like adding instant redemption, adding deposit assets or shipping an audit fix. Proxy upgrades have no timelock. They're controlled by the ProxyAdmin multisig, which typically needs 4 of 6 signatures from the asset issuer, Upshift and the curator (2 signers each), so no single party can upgrade a vault alone. The proxy pattern follows EIP-1967.

3. Audits

Question. Which firms have audited the contracts, covering which code, and when?

A strong answer lists each audit with its date, scope and public report, including new vault types as they shipped.

How Upshift answers. Upshift's contracts have been through 10 smart contract audits by 6 independent firms: Halborn, Hacken, OtterSec, ChainSecurity, Sigma Prime and Zellic. Hacken's five reviews between September 2025 and April 2026 covered the core contracts, the AllocationWhitelist, the instant-redemption subaccount and the Atomic Vault, and Halborn reviewed the Stellar vault in April 2026. Reports are linked from the audits page in the Upshift docs. Audits reduce smart contract risk without removing it.

4. Pricing and NAV

Question. Who calculates the value of a share, and can the party running the strategy mark its own positions?

A strong answer separates pricing from strategy and uses more than one price source.

How Upshift answers. Upshift's multi-oracle engine prices every position in the vault, and the curator doesn't set the NAV. Vaults follow the ERC-4626 tokenized vault standard for deposits, shares and redemptions.

5. Strategy limits

Question. What stops the curator or operator from deploying funds somewhere the mandate doesn't allow?

A strong answer describes limits enforced before a transaction executes, set at a level of detail finer than "approved protocols", and identifies who can change them.

How Upshift answers. August's policy engine restricts deployment by chain, protocol, token and contract function, and checks each deployment against those rules before it goes through. A curator can allocate inside the mandate and can't reach anything outside it. Each vault carries its own mandate, and tiering vault strategies by risk covers how fintechs build a low, mid and higher-yield menu from them.

6. Redemptions and liquidity

Question. How fast can customers get their money back, in which asset, and what happens if many redeem at once?

A strong answer gives the standard redemption timeline, any faster route and its cost, and the asset the redemption pays out in.

How Upshift answers. Upshift processes claimable redemptions daily, and each vault has its own lag, published in its withdrawal terms. Most vaults also offer instant redemption for a fee, subject to available liquidity. Multi-asset vaults accept several deposit assets but have one reference asset, and every redemption pays out in that asset, so a depositor who came in with USDT may exit in USDC. For tokenized assets, Upshift Clear provides an instant, oracle-priced USDC exit.

7. Compliance

Question. Who can deposit, how are customers screened, and are the fintech's customer funds kept apart from other depositors?

A strong answer covers screening at the front end, a way to restrict the vault to approved addresses, account segregation and the regulatory framework in each target market.

How Upshift answers. Upshift's frontend runs KYC and AML checks. Whitelisted and sole-depositor (private) vaults restrict deposits to approved addresses, and segregated vault accounts keep one client's allocation apart from a shared pool. For platforms serving EU customers, the licensing questions under MiCA are set out in MiCA licence: who needs one, alongside ESMA's MiCA pages.

8. Reporting

Question. Can the vault's positions and performance be verified by someone other than the provider?

A strong answer offers onchain data plus an independent party's reporting that an auditor or board can rely on.

How Upshift answers. Vault contracts, share supply and owner addresses are readable onchain. Securitize provides independent third-party reporting on Upshift vaults at an LP's request.

9. Insurance

Question. Is there insurance against a smart contract failure?

A strong answer states plainly what cover exists and what doesn't, and where additional cover can be bought.

How Upshift answers. There's no smart contract insurance at protocol level. A fintech or its depositors can buy cover from third-party providers, and onchain insurance covers how those policies work and what they pay out on.

10. Track record

Question. Which institutions already run on the platform, and at what scale?

A strong answer names live, public integrations and gives dated figures that can be checked.

How Upshift answers. As of September 2026, Upshift had reached over $550M in peak TVL across more than 50 vaults on over 30 chains, with more than 66,000 users. Kraken Institutional runs custom vaults on Upshift, announced in July 2026, and SDK integrations are live with Tria and app.monad.xyz. Case studies for Kraken and Tria describe each setup. Upshift raised a $10M Series A led by Dragonfly in March 2025.

Running a vendor review? Upshift answers DD questionnaires directly with the risk and compliance teams running them.

Talk to the Upshift team

Summary for a DD file

Area

Question

Upshift's answer

Custody

Who can move funds?

Non-custodial; Gnosis Safe owner, MPC-signed operator, no guardian role

Emergency powers

What can emergencyWithdraw reach?

Vault-held assets only, sent to an owner-specified address

Parameter changes

Do they wait?

Configurable per-vault timelock; instant-redemption and withdrawal fees exempt

Code upgrades

Who approves them?

ProxyAdmin multisig, typically 4 of 6 across issuer, Upshift and curator; no timelock

Audits

Who reviewed the code?

10 audits by 6 firms, reports in the docs

NAV

Who prices positions?

Upshift's multi-oracle engine, separate from the curator

Strategy limits

What bounds the curator?

Policy engine by chain, protocol, token and contract function

Redemptions

How fast, in what?

Daily processing, per-vault lag, instant for a fee subject to liquidity, one reference asset

Compliance

Who can deposit?

Frontend KYC and AML; whitelisted and sole-depositor vaults; segregated accounts

Reporting

Independent verification?

Onchain data; Securitize reporting at LP request

Insurance

Is there cover?

None at protocol level; third-party cover can be bought

Track record

Who runs on it?

$550M+ peak TVL, 66k+ users, Kraken Institutional, Tria

Every onchain vault carries smart contract, oracle, bridge and counterparty risk, and yields float with market conditions and are never guaranteed. Always make sure to do your own research and be aware of the above and any other risks before depositing.

Frequently asked questions

What is vault provider due diligence?

It's the vendor review a fintech runs before integrating a stablecoin vault provider, covering custody, contract controls, audits, pricing, strategy limits, redemptions, compliance, reporting, insurance and track record.

Are Upshift vault upgrades timelocked?

No. Proxy upgrades change the vault's code and have no timelock; they typically need 4 of 6 signatures on the ProxyAdmin multisig, split between the asset issuer, Upshift and the curator. Parameter changes such as the management fee sit behind a configurable per-vault timelock.

Who controls an Upshift vault?

A Gnosis Safe multisig owns each vault and appoints the operator, whose MPC-signed transactions pass a maker-checker approval and the policy engine's limits on chains, protocols, tokens and contract functions.

How often are redemptions processed?

Upshift processes claimable redemptions daily, and each vault publishes its own lag. Most vaults also offer instant redemption for a fee, subject to liquidity.

Do Upshift vaults have insurance?

There's no smart contract insurance at protocol level. Cover can be bought from third-party providers.

Can a fintech restrict a vault to its own customers?

Yes. Whitelisted and sole-depositor vaults limit deposits to approved addresses, and segregated accounts keep a client's allocation apart from shared pools.

Keep reading

Share this post:

Launch a vault with Upshift

Upshift builds custom, permissioned vaults for custodians, exchanges, neobanks and asset managers. Tell us what you are building and the team will follow up.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.