Gemini announced on January 29, 2019 that it had completed a SOC 2 Type 1 examination conducted by Deloitte & Touche LLP. According to the cryptocurrency exchange and custodian, the work evaluated the design and implementation of security controls covering systems used to trade and safeguard customer assets.

The development mattered because centralized crypto venues were asking retail customers and institutions to entrust them with private-key custody while the industry lacked a uniform, public method for comparing operational safeguards. A recognized service-organization examination gave counterparties a familiar assurance framework, although it did not eliminate custody, cybersecurity or business risk.

What Deloitte examined

Gemini said it engaged Deloitte during 2018 and completed the examination after several months of preparation and external review. The disclosed scope included Gemini’s exchange application, infrastructure and underlying customer database, together with the cryptocurrency storage system holding private keys for its online and offline wallets.

The American Institute of Certified Public Accountants defines SOC 2 examinations as reports on service-organization controls relevant to security, availability, processing integrity, confidentiality or privacy. Gemini said Deloitte inspected its controls against AICPA trust-services criteria, but the company’s public announcement did not identify every criterion selected, reproduce the auditor’s opinion or disclose the control-by-control findings.

Gemini characterized itself as the first cryptocurrency exchange and custodian to complete this level of examination. CoinDesk’s contemporaneous report accurately presented that distinction as Gemini’s claim. Coinburn could not verify the superlative through a comprehensive January 2019 inventory of every exchange and custody provider, so it should not be treated as an independently established industry ranking.

Why Type 1 mattered—and where it stopped

A Type 1 examination addresses whether a system description is fairly presented and whether relevant controls are suitably designed and implemented as of a specified date. It is therefore a point-in-time assessment. It does not provide the extended-period testing of operating effectiveness associated with a Type 2 examination.

That distinction was especially important for cryptocurrency custody. A control can be appropriately designed on paper and present when examined without proving that it will operate consistently during attempted intrusions, employee departures, key-recovery events or periods of market stress. SOC 2 also does not establish asset reserves, solvency, market liquidity or the legal treatment of every customer claim.

Gemini said on January 29 that it intended to pursue a Type 2 examination during 2019 and undergo SOC 2 examinations annually. Those were forward-looking commitments on the event date, not completed evidence of sustained control performance.

Institutional context

The New York State Department of Financial Services records Gemini Trust Company as holding a limited-purpose trust charter granted in October 2015. That regulatory status and the SOC 2 examination addressed different questions. The charter established Gemini’s supervised institutional form in New York; the Deloitte work addressed specified controls within the examined systems. Neither record should be used as a substitute for the other.

For institutions evaluating digital-asset counterparties, the January 29 announcement nevertheless represented a meaningful step toward the assurance practices used for established financial and technology service providers. It supplied a structured external examination rather than relying entirely on an exchange’s unsupported description of its security architecture.

The surviving public record remains incomplete. The Deloitte report itself was not published, and the announcement did not state its precise point-in-time assessment date, any exceptions found or which parties could obtain the restricted report. The defensible event-day conclusion is therefore narrow: Gemini announced completion of a Deloitte SOC 2 Type 1 examination covering its exchange and custody control environment, while evidence about sustained effectiveness remained outstanding.

Primary sourceGemini — SOC 2 Type 1 examination announcement

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.