Security Architecture

Non-custodial by design. Your funds settle directly to your wallets through smart contracts you control.

On-chain verification

Settlement contracts deploy on public blockchains with full source verification. Every payout independently auditable — no trust required.

What will be published

  • →Verified smart contract addresses on supported networks
  • →Full contract source code and ABI
  • →Third-party security audit reports
  • →Block explorer links for every settlement

Threat Model: What an Attacker Cannot Do

If TandemPay Servers Are Compromised

An attacker with full server access could:

  • ✓Disrupt payment processing (denial of service)
  • ✓Access merchant dashboard data and logs
  • ✓Potentially leak sensitive business information

Smart Contracts Protect Funds

An attacker with full server access cannot:

  • ✗Steal deposit funds — smart contracts hardcode destinations
  • ✗Redirect settlements — wallet addresses are immutably encoded
  • ✗Access wallet keys — TandemPay never stores them

Non-Custodial Settlement

TandemPay does not hold custody of merchant funds. Settlements are executed through smart contracts with hardcoded destination addresses provided by merchants during setup.

Smart Contract Enforcement

All fund movement is enforced by on-chain smart contracts, not by server code. Even if TandemPay servers are compromised, funds can only flow to merchant-specified addresses.

On-Chain Transparency

All settlements are publicly verifiable on supported blockchains. Merchants can independently verify every transaction without trusting TandemPay infrastructure.

No Key Storage

TandemPay does not store or have access to merchant wallet private keys. Merchants maintain exclusive control over their settlement wallets.

How Non-Custodial Settlement Works

1

Merchant Configuration

During onboarding, merchants provide wallet addresses where they want funds delivered. These addresses are recorded in smart contracts deployed for that merchant.

2

Card Payment Processing

Customers pay with cards through TandemPay's payment gateway. Card processing happens through traditional payment networks (Visa, Mastercard, etc.).

3

Stablecoin Conversion

After the card transaction clears, TandemPay converts the fiat amount (minus fees) into stablecoins. This conversion happens off-chain through liquidity providers.

4

Smart Contract Settlement

Stablecoins are sent to the merchant's smart contract, which immediately executes settlement to the hardcoded wallet addresses. TandemPay servers cannot redirect or freeze these funds — the settlement path is enforced by immutable smart contract code.

5

Merchant Receives Funds

Funds arrive directly in merchant-controlled wallets. Merchants can verify settlement by checking the blockchain, independent of TandemPay's infrastructure.

Merchant Responsibilities

⚠ Wallet Security is Your Responsibility

While TandemPay's non-custodial architecture protects funds from server compromise, merchants are solely responsible for securing their wallet private keys.

Best Practices:

  • Use hardware wallets or secure key management systems
  • Never share private keys with anyone, including TandemPay support
  • Implement multi-signature wallets for high-value settlements
  • Regularly verify wallet addresses in your merchant dashboard
  • Test with small amounts before processing large volumes

TandemPay cannot recover lost or stolen private keys. If you lose access to your wallet, funds settled to that address are permanently inaccessible.

Payment Data Security

TandemPay handles sensitive card payment data according to industry standards:

  • PCI DSS Level 1 compliant payment processing
  • End-to-end encryption for card data in transit
  • Tokenization of payment information
  • Regular security assessments and penetration testing

Merchants integrate with TandemPay's payment gateway without handling raw card data, reducing PCI compliance scope.

Security Questions?

For detailed security documentation or responsible disclosure of vulnerabilities, contact:

Contact Security Team

See also: security.txt