TLS 1.3 supported
All traffic to TriaPay is served over TLS with HSTS preloaded. Plain HTTP requests are redirected, never accepted. TLS 1.3 is supported alongside TLS 1.0–1.2; modern cipher suites are enforced and weak ciphers are disabled.
A plain summary of the controls in place. For a deeper review, contact the team.
All traffic to TriaPay is served over TLS with HSTS preloaded. Plain HTTP requests are redirected, never accepted. TLS 1.3 is supported alongside TLS 1.0–1.2; modern cipher suites are enforced and weak ciphers are disabled.
Tenant secrets, API keys, and exchange credentials are stored encrypted with a key held outside the database. A database dump alone reveals no secret material.
Passwords are hashed with a memory-hard function tuned to OWASP guidelines. Two-factor authentication via authenticator apps and one-time backup codes is available on every account.
Every authentication event, credential rotation, credit, refund, and admin action is recorded with timestamp, actor, IP address, and detail payload. Logs are retained for 180 days and queryable from the dashboard.
TriaPay watches the chain and triggers your DHRU balance crediter. Funds settle directly to addresses you control. We never hold customer funds in our custody.
Operational runbooks and incident response procedures are maintained internally and reviewed regularly.