Abstract: The present disclosure relates to a system and method for providing secure access to an asset, for example, in the form of a cryptographic key needed to perform cryptographic operations, such as signing transactions of digital assets. The system makes use of three interrelated data objects; a policy object that defines access control rules, one or more online vault objects that are linked to the policy object, and one or more assets that are linked to one of the vault objects. The policy object and the assets are all created in a cold storage environment, with their integrity being protected using a key-based cryptographic technique. The vault object is created in an online environment, wherein a cryptographic hash is used to generate a vault ID, with specific data fields within the vault object being used as inputs to the hash function.