Skip to main content
Some products list features. This page lists refusals — because each one is load-bearing for the guarantees on the rest of the site.

We never hold your money

What that rules out

No balance held on your behalf, no escrow, no rolling reserve.

What you get instead

No counterparty risk. Our insolvency, outage, or bad decision cannot strand your funds.
Concretely: the function that releases your funds is callable by anyone. We hold no key and no on-chain power to block it, so we cannot withhold what is already in your pool, and neither could a regulator ordering us to. Two honest limits sit alongside that:
  • A minimum before a batch pays out. Your pool only splits and credits once its undistributed balance reaches 1.00 of the settlement token. Below that the call reverts, and the amount simply rolls forward into the next batch rather than being released on its own.
  • A payment we decline to move. If you switch payer screening on in enforce mode, a payment whose sender hits a sanctions list is left where it is instead of being moved into your pool. The on-chain step stays open to anyone, but we won’t perform it, and there is no self-service release today. See sanctions.

We can’t reverse a payment

Once confirmed, a payment is final. Nothing goes back to the payer, their bank, us, or you. That’s protection against fraudulent chargebacks and, equally, the reason refunds are something you send manually. Settlement can still be paused, though, and you should know the two cases. When a customer pays by sending funds to the invoice address we show them, we don’t move that payment into your pool if payer screening is on in enforce mode and the sender hits a sanctions list, or if our indexer sees the settlement address it expected disagree with the one on record. The money stays at the invoice address and the on-chain step remains callable by anyone, but there is currently no way to release a held payment from inside the product — you’d need to contact us. Neither case can send funds anywhere except your pool.

We don’t do KYC

No identity documents from you or your customers. Sanctions screening checks a wallet address against a public list — a lookup on a public identifier, not identity verification. Sanctions.
If your business requires customer identity verification, that’s your obligation to meet in your own flow. We neither provide it nor prevent it.

We don’t touch fiat

No on-ramps, no off-ramps, no conversion to or from bank money. Not offered, not integrated, not recommended.
This is a firm line rather than a missing feature. Facilitating conversion between crypto and fiat is what pulls a business into a different regulatory category, with obligations that would change the product fundamentally — including the custody model everything else depends on. Cashing out is between you and whichever exchange or service you choose.

We don’t convert volatile assets at checkout

Today the product is stablecoin-only: USDC, USDT, EURC. A customer can’t pay in ETH and have it swapped to USDC on the way in. Accepting volatile assets means someone bears price risk between payment and settlement, and the swap can fail if liquidity moves. It is not committed work and has no date — we’d rather get it right than get it out. Roadmap.

We don’t lend, stake, or invest your balance

Funds sit in your pool. They are not deployed anywhere, and generate no yield. If a payment processor offers yield on your balance, ask where the yield comes from — it comes from doing something with your money that you can’t do while it’s genuinely yours.

We don’t have an admin key

Your pool has no owner, no upgrade path, and no pause function. There’s no privileged key over the money to steal, subpoena, or misuse — including by us. Once funds are in the pool, the release call is open to anyone and we can’t stop it or redirect it. We do keep one account-level control, and it’s worth naming: a platform admin can deactivate your merchant account, which stops your hosted checkout and API from creating new payments. It doesn’t touch money already in your pool — that stays fully distributable — and the action is written to the audit log. The trade-off is honest: no undo button. You also can’t mistype a payout address, because there isn’t one to type. Your payout address is the wallet you sign in with — one for EVM chains, one for TRON — and at pool setup you sign a one-time proof-of-control message from that exact wallet before it’s baked into your pool’s permanent address. It can’t be changed afterwards.

What we do claim

On-chain verification, with its conditions

A real mechanism with real limits, stated plainly.
We describe security as mechanisms with conditions, never as guarantees of invulnerability. Any vendor telling you their system cannot be compromised is telling you they haven’t thought about it carefully.