Non-custodial by default
Private keys are generated and stored exclusively on user devices. ClearPayz has no operational capability to move user funds. There is no admin override.
Security & Compliance
ClearPayz is non-custodial by architecture and regulated by partnership. Funds remain provably yours; movement is governed by licensed counterparties, hardware-backed key management, and continuous third-party audit.
Risk score · 12
Risk score · 58
0
Customer funds held by ClearPayz
100%
Keys generated client-side
24/7
On-call security response
SOC 2
Type II in progress
Operating principles
These aren't policies. They're architectural constraints — enforced in the codebase, in our vendor selection, and in every partnership we sign.
Private keys are generated and stored exclusively on user devices. ClearPayz has no operational capability to move user funds. There is no admin override.
Where regulated activity is required — card issuing, fiat on/off-ramps, virtual accounts, settlement — ClearPayz operates through licensed counterparties across IN, AE, SG, EU, and UK.
Smart contracts are audited and verified on-chain. Reserve attestations for stablecoin float are published quarterly. Trust is established through verification, not marketing.
KYC, KYB, sanctions screening, and transaction monitoring run as first-class systems across every product, reviewed by a dedicated compliance officer.
Security layers
Private keys are generated and stored exclusively on your device. ClearPayz never has access to your seed phrase or keys.
All data is encrypted in transit via TLS 1.3 and at rest using AES-256. API keys and secrets are stored in hardware security modules.
Every transaction is screened in real time against sanctions lists, PEP databases, and risk rules before settlement.
Production infrastructure runs on hardened cloud environments with network segmentation, intrusion detection, and 24/7 monitoring.
Role-based access, multi-factor authentication, and audit logging across all internal systems and API operations.
FIU-IND reporting, AML/CFT programme, and FATF-aligned controls — overseen by a designated MLRO.
Compliance programme
ClearPayz performs FIU-IND reporting and operates in line with India's AML/CFT framework.
A full Anti-Money-Laundering and Counter-Financing-of-Terrorism programme aligned with FATF guidance, overseen by a designated MLRO.
Identity and business verification, sanctions and PEP screening on every participant.
Real-time screening and risk scoring across every transaction on the platform.
Independent audits
| Firm | Scope | Date | Outcome |
|---|---|---|---|
| Trail of Bits | Smart-contract & cryptographic review | March 2026 | All high-severity findings resolved |
| Halborn | Mobile wallet & key-derivation audit | January 2026 | Zero critical, two informational |
| Cure53 | Web application penetration test | November 2025 | Clean report; published with permission |
| Big-4 firm (in progress) | SOC 2 Type II observation window | Ongoing through Q3 2026 | Quarterly control attestations available |
ClearID
ClearID handles KYC, KYB, liveness detection, and sanctions screening — integrated into every ClearPayz product.
Learn more at ClearID
Responsible disclosure
If you discover a security vulnerability in ClearPayz products or infrastructure, please report it responsibly to our security team. We commit to acknowledging reports within 48 hours and working with researchers to resolve issues promptly.
security@clearpayz.comDiligence questionnaires, partner security reviews — we respond within one business day.