Security Architecture
ZPAY is built with a zero-trust, non-custodial architecture from the ground up. No user funds ever touch our servers — the protocol enforces this at the cryptographic layer.
Non-Custodial by Design
Your private keys never touch our infrastructure. Every transaction is signed locally on your device or HSM before it is broadcast to the Stellar network. We hold zero custody over user funds at any point.
Audited Soroban Contracts
All escrow, split, and routing smart contracts are written in formally-verified Rust, compiled to WASM, and independently audited by third-party security firms. Contract source is open and immutable once deployed.
Real-Time Threat Monitoring
24/7 automated on-chain anomaly detection continuously monitors transaction patterns. Unusual activity triggers instant circuit breakers — pausing contract execution without requiring human intervention.
MPC Key Architecture
Multi-Party Computation distributes cryptographic key shares across geographically separated nodes. No single server holds a complete key, eliminating single points of compromise at the infrastructure layer.
Security Controls & Standards
Immutable Audit Trail
Found a vulnerability?
Responsible disclosure is rewarded. Critical vulnerabilities in our smart contracts or API infrastructure qualify for payouts up to $50,000 USD.
GetStarted.
Fast, secure, and borderless payments powered by ZPAY on Stellar.
Connect
© 2026 ZPAY Technologies. All rights reserved.