Skip to main content
Security

How TriaPay protects your funds

A plain summary of the controls in place. For a deeper review, contact the team.

01

TLS 1.3 supported

All traffic to TriaPay is served over TLS with HSTS preloaded. Plain HTTP requests are redirected, never accepted. TLS 1.3 is supported alongside TLS 1.0–1.2; modern cipher suites are enforced and weak ciphers are disabled.

02

Encrypted at rest

Tenant secrets, API keys, and exchange credentials are stored encrypted with a key held outside the database. A database dump alone reveals no secret material.

03

Modern password hashing

Passwords are hashed with a memory-hard function tuned to OWASP guidelines. Two-factor authentication via authenticator apps and one-time backup codes is available on every account.

04

Full audit log

Every authentication event, credential rotation, credit, refund, and admin action is recorded with timestamp, actor, IP address, and detail payload. Logs are retained for 180 days and queryable from the dashboard.

05

No custodial holding

TriaPay watches the chain and triggers your DHRU balance crediter. Funds settle directly to addresses you control. We never hold customer funds in our custody.

Operational runbooks and incident response procedures are maintained internally and reviewed regularly.