Security at Cryptain

The controls that protect your account, your integrations and your customers' payments.

A payment service is only as good as the trust behind it. This page sets out how Cryptain is protected, and what you can do to keep your own account safe.

Signing in

  • Two-factor authentication with any authenticator app, plus single-use recovery codes. Administrators cannot use the admin panel without it.
  • Passkeys let you sign in with your fingerprint, face or device PIN instead of a password.
  • Password storage uses a slow, salted one-way hash. Nobody at Cryptain can read your password.
  • New sign-in alerts by email whenever your account is used from an unfamiliar network.
  • Rate limits and bot protection on login, sign-up and contact forms stop password guessing and automated abuse.
  • Session timeout after two hours of inactivity.

Moving money

  • Address locks. A newly saved withdrawal address cannot be used for a set number of hours, and you are emailed when one is added. If someone gets into your account, they cannot empty it straight away.
  • Two-factor confirmation for withdrawals, refunds and mass payouts.
  • Address checks. Every address is validated for its network before it is saved, which prevents the most common costly mistakes.
  • Own-wallet settlement. On plans that include it, payments go straight to your wallet. We only ever see public addresses or an extended public key, never private keys or seed phrases.

API and integrations

  • Signed requests. Each API call is signed with HMAC-SHA256 over the timestamp, method, path and body. A request cannot be altered in transit or replayed later.
  • Scoped keys. Create read-only keys for reporting, and restrict any key to the IP addresses of your servers.
  • Idempotency keys make retries safe: the same request never creates two invoices.
  • Signed webhooks with a timestamp, so your server can prove a notification came from us. Our plugins also re-read the invoice from the API before changing an order.

Inside Cryptain

  • Encryption. All traffic uses HTTPS. API secrets, webhook secrets and third-party credentials are encrypted in the database.
  • Least privilege. Team members get only the access their role needs: manager, finance, developer, viewer or cashier.
  • Audit log. Sign-ins, setting changes, withdrawals and admin actions are recorded with time and IP address.
  • Backups of the database are taken automatically, and the secrets inside them stay encrypted.
  • Browser protections. A strict content security policy, frame protection and secure cookies reduce the risk of cross-site attacks.

Your part

  1. Turn on two-factor authentication under Security, or add a passkey.
  2. Keep API secrets and webhook secrets on your server, never in front-end code or public repositories.
  3. Always verify webhook signatures before marking an order paid.
  4. Restrict API keys to your server's IP address where you can.
  5. For larger amounts, settle to a hardware wallet using own-wallet settlement.

We will never ask for your password, two-factor codes or seed phrase, by email, chat or phone.

Reporting a vulnerability

If you believe you have found a security issue, please tell us privately through the contact form with the subject "Security". Give us a reasonable time to fix it before disclosing it. We will not take action against good-faith research that avoids harm to users and their data.

Open an account in two minutes

Başlamak ücretsiz. Ödeme başına %1. İstediğiniz zaman yükseltin.