Security

Built so that one mistake cannot move your money

Money movement needs a passkey, sensitive changes need two people, and every balance is reconciled against what actually happened on the chain.

How we protect your funds

Passkeys guard money movement

Withdrawals, withdrawal addresses, webhook URLs, settlement settings and API keys all require a passkey confirmation from the account owner — a stolen password is not enough.

Two-person approval

Sensitive operations on our side — releasing held funds, freezing accounts, approving payouts, changing upstream costs — need a second reviewer before they take effect, and every one is audited.

Every payment verified

Payments are checked against the chain independently of any upstream report, and balances are reconciled continuously. Payouts pause automatically if reserves ever fall short.

Your ledger, kept separate

Each merchant has its own balance and ledger, with every entry traceable to an order, a settlement or a payout. Team members get only the roles you give them.

Account protection

  • Sign in with a passkey, a password (optionally with an authenticator app), or a one-time email code.
  • Adding or removing a passkey or authenticator first requires a code sent to your email, and a new passkey is announced by email.
  • Team roles limit who can see balances, create API keys or request withdrawals.
  • API secrets are encrypted at rest and shown only once, when you create them.

Know your business

  • Every merchant is verified before going live; documents are stored encrypted and kept for a fixed retention period.
  • Pricing and limits are confirmed per merchant during onboarding.
  • Questions about security or compliance? Email ops@routepays.com.

Start accepting payments with RoutePays

Open an account in minutes. Our team reviews your business and gets you live.