Security
Built so that one mistake cannot move your money
Money movement needs a passkey, sensitive changes need two people, and every balance is reconciled against what actually happened on the chain.
How we protect your funds
Passkeys guard money movement
Withdrawals, withdrawal addresses, webhook URLs, settlement settings and API keys all require a passkey confirmation from the account owner — a stolen password is not enough.
Two-person approval
Sensitive operations on our side — releasing held funds, freezing accounts, approving payouts, changing upstream costs — need a second reviewer before they take effect, and every one is audited.
Every payment verified
Payments are checked against the chain independently of any upstream report, and balances are reconciled continuously. Payouts pause automatically if reserves ever fall short.
Your ledger, kept separate
Each merchant has its own balance and ledger, with every entry traceable to an order, a settlement or a payout. Team members get only the roles you give them.
Account protection
- Sign in with a passkey, a password (optionally with an authenticator app), or a one-time email code.
- Adding or removing a passkey or authenticator first requires a code sent to your email, and a new passkey is announced by email.
- Team roles limit who can see balances, create API keys or request withdrawals.
- API secrets are encrypted at rest and shown only once, when you create them.
Know your business
- Every merchant is verified before going live; documents are stored encrypted and kept for a fixed retention period.
- Pricing and limits are confirmed per merchant during onboarding.
- Questions about security or compliance? Email [email protected].
Start accepting payments with RoutePays
Open an account in minutes. Our team reviews your business and gets you live.