How we protect a merchant account
You fund a prepaid wallet, we fulfill under your label, and lot certificates stay tied to the shipment. This page is the merchant view. It is not a certification or a legal opinion. Availability is on the status page.
Apply as a MerchantAccount sign-inEmail codes or password, plus extra checks on money and admin actions.
The portal supports authenticator enrollment. Sensitive administrator and financial actions require a recent higher-assurance session where enforcement is enabled. Use the security settings shown in your account.
Sanctions screeningRequired checks fail closed if the dataset is stale.
Onboarding and transactions that require sanctions screening fail closed when the configured OFAC dataset is missing, incomplete, or stale. A potential match needs review. That is not a legal determination.
Wallet and invoicesRetries do not silently double-charge.
Money workflows use uniqueness and idempotency records so a retry can be reconciled instead of treated as a second instruction. Invoices keep the plan and price snapshot from the day they were created.
Bitcoin addressesEach deposit gets its own address.
Receiving addresses are derived from encrypted extended public-key material. Merchant top-up, guest checkout, and tip keyspaces are separate. The application is not configured with spending private keys.
Reporting a security issue
Use the Contact us flow with a description and reproduction steps. Do not file a public GitHub issue first.