Trust & security

Your funds. Your keys.
Your move.

Coinpay is non-custodial by design. We hand you the cryptographic keys at signup; payments settle directly to addresses you control. We never hold a single sat of customer money.

How we protect you

Four principles. Zero exceptions.

The architecture behind every transaction.

01

Non-custodial by default

Keys are generated client-side at account creation. Our servers receive a public address — never a private key, mnemonic, or signed transaction template. If we vanished tomorrow, your funds are still in your wallet.

Self-sovereign
02

Defense-in-depth infrastructure

AWS GovCloud regions, hardware-backed HSMs, mTLS everywhere, and zero-trust network policies. Every internal call is authenticated; every secret has a 30-day rotation; every deploy is signed.

SOC 2 Type II
03

Transparent, auditable code

Our payment-handling smart contracts are open source, formally verified, and audited annually by Trail of Bits and Zellic. Reports linked below; we don't ship contract changes without a fresh audit.

Open source
04

Compliance without surveillance

FCA-registered crypto-asset business. KYC and Travel Rule are scoped to you, the merchant — your customers don't fill out forms to pay. We share with regulators only what UK law requires, and we publish every request.

FCA registered
Certifications

Audited. Certified. Verified.

Trust report PDF
SOC 2
SOC 2 Type II

Audited Apr 2025 by Prescient Assurance.

Type II report on request
FCA
FCA registered

UK Crypto-asset business · Reg. 1011247.

5MLD & Travel Rule compliant
27001
ISO 27001

Stage 2 audit underway. Cert. expected Q2 2026.

Stage 1 complete · in progress
GDPR
GDPR compliant

EU/UK data only. DPA available; DPO on staff.

Sub-processors listed publicly
PCI
PCI DSS 4.0

SAQ-A scope for the (rare) card flows we expose.

Most flows have zero card scope
HIPAA
HIPAA-ready

BAAs available for healthcare merchants on Enterprise.

On request
Architecture

What happens when a customer pays.

Customer wallet
End user
Coinpay edge
TLS 1.3 · DDoS · WAF
API service
mTLS · rate-limited · audit-logged
Public blockchain
Settlement layer · BTC / ETH / SOL
  • No private keys ever cross our network
  • Contracts audited by Trail of Bits + Zellic
  • Webhooks signed with HMAC-SHA256
Your wallet
Funds settle here directly

Have a question we didn't answer?
Our security team replies in < 24 hours.

Contact security