Defense in depth

Security is the foundation, not a feature.

Apay is custodial-by-design: private keys live in hardened infrastructure, while the app delivers safe, friendly interactions. Every layer — device, transport, contract and process — is built to protect assets and data.

9:41Security
Account protection
All checks active
Face ID · Tx password · Device lock
KYC L2 verified
Passed
Certificate pinning
On
Trusted device
Bound
Layered defense

Control areas

Six layers working together to keep APAY and user data safe.

🔐

Key custody (HSM / KMS)

Keys are generated and stored in hardware security modules and never leave the backend. The app only calls signed APIs.

✍️

Multi-sig & escrow contracts

ApayToken, EscrowWallet and MultiSigWallet contracts ensure transfers and C2C releases require proper authorization on-chain.

📱

Device & auth security

Biometric unlock, a separate 6-digit transaction password, device binding and remote device logout protect account access.

🔏

Transport security

All traffic uses HTTPS with certificate pinning; sensitive fields (passwords, tx passwords) are encrypted in transit and at rest (AES-256).

🚫

Tamper resistance

Root/jailbreak detection blocks sensitive operations on compromised devices; code obfuscation and anti-debug guard the app.

🧾

Auditability

Security logs capture logins, password changes and asset movements; anomaly detection flags new-device and remote logins.

Compliance

Aligned to India's framework

Compliance is designed in from day one, not bolted on.

🪪

Tiered KYC

L1 phone, L2 document (OCR) and L3 bank verification. C2C trading requires at least L1+L2; higher tiers unlock more capabilities.

L1 phoneL2 OCRL3 bank
⚖️

AML thresholds

Large transfers (e.g. > ₹10,000) trigger additional verification. Suspicious patterns are reviewed by the risk admin role.

Risk adminThreshold checks
🗄️

Data residency

India user data — including KYC documents — is stored on India-region servers, aligned with the Personal Data Protection framework (PDPB).

India regionPDPB aligned
🤝

Dispute arbitration

C2C disputes are adjudicated by platform admins with evidence review; on-chain refunds execute automatically based on the ruling.

Evidence reviewAuto refund
🛡️

Private chain model

Running on a Polygon private chain removes dependence on public CBDC regulation while keeping funds protected by contract logic.

No CBDC overlapFund safety first
👥

Five-role admin

Super, operation, finance, support and risk admins separate duties across the back office for least-privilege operations.

Least privilegeSegregated duties
Process

How a transfer is protected

1

Authenticate

Biometric + tx password

2

Authorize

Backend validates & rate-limits

3

Sign

HSM/KMS signs the tx

4

Escrow / Multi-sig

Contract enforces rules

5

Confirm

<3s on-chain, pushed to app

Security questions?

We're happy to share the full threat model and architecture brief with partners and auditors.