Data Encryption

AES-256 encryption at rest

Industry-standard encryption for all stored data. Your sensitive information is encrypted using AES-256, the same encryption used by banks and governments worldwide.

TLS 1.3 for data in transit

All data transmitted between your browser and our servers uses TLS 1.3, the latest and most secure version of transport layer security.

End-to-end encrypted API calls

Every API request and response is encrypted end-to-end. Even if intercepted, the data remains unreadable to attackers.

Secure key management

Encryption keys are managed through Vercel's secure environment variables system with automatic rotation and access controls.

Infrastructure Security

Hosted on Vercel

SOC 2 Type II and ISO 27001 certified infrastructure. Enterprise-grade security with automatic SSL and DDoS protection.

  • Automatic security updates
  • Global CDN 100+ edge locations
  • Zero-downtime deployments
Database on Supabase

SOC 2 compliant and GDPR ready PostgreSQL database with built-in security features.

  • Row-level security policies
  • Automatic daily backups
  • Point-in-time recovery
DDoS protection

Enterprise-level DDoS mitigation via Cloudflare handling 100+ million requests per second.

Multi-region redundancy

Data replicated across multiple geographic regions for high availability and disaster recovery.

Smart Contract Security

No custom smart contracts

We use standard, battle-tested USDC token contracts. No custom code means no custom vulnerabilities.

Client-side transaction signing

All transactions are signed in your browser using your wallet. Your private keys never leave your device.

Non-custodial architecture

Funds go directly from customer wallet to merchant wallet. StablePay never has access to move, freeze, or hold your money.

Blockchain verification

Every payment is publicly verifiable on the blockchain. Full transparency and immutable audit trail.

Security Roadmap 2025-2026

Built in NYC, securing payments globally. Our ongoing security initiatives:

  • SOC 2 Type II certification (Q2 2026 target)
  • Independent smart contract audits (Q1 2026)
  • Bug bounty program launch (Q4 2025)
  • Penetration testing quarterly
  • ISO 27001 certification (2026)

GDPR Compliance

Data minimization

We only collect data that's essential for payment processing. No unnecessary tracking or profiling.

Right to access your data

Request a full export of all your data at any time through your dashboard or by contacting support.

Right to delete your data

Request complete deletion of your account and associated data. We retain only legally required transaction records.

EU data residency

Available on enterprise plans. Store your data exclusively in EU data centers for full GDPR compliance.

Data We Collect

Order details

Essential transaction information for payment processing:

  • Payment amount in USDC
  • Blockchain network used
  • Timestamp of transaction
  • Order reference ID
Transaction hashes

Public blockchain transaction IDs. This data is already public on the blockchain and allows payment verification.

Merchant account info

Email, company name, and wallet addresses for merchants accepting payments.

We NEVER collect sensitive data

Your security is paramount. We never collect:

  • Private keys or seed phrases
  • Wallet passwords
  • Credit card information
  • Social security numbers

Data Retention

Transaction data (7 years)

Required by financial regulations for audit and compliance purposes. Includes payment amounts, timestamps, and transaction IDs.

Order history (indefinite)

Merchants have permanent access to their order history for business records and customer support.

Server logs (90 days)

Technical logs for debugging and security monitoring. Automatically deleted after 90 days.

Account data (until deleted)

Your account information is retained until you request deletion. You can export or delete your data anytime.

Payment Flow

1. Customer initiates payment

Customer clicks 'Pay with Crypto' on merchant's checkout page. StablePay payment modal opens with order details and supported networks.

2. Wallet connection

Customer connects their Web3 wallet to confirm payment:

  • MetaMask for EVM chains (Ethereum, Polygon, Base, Arbitrum)
  • Phantom for Solana
  • WalletConnect for mobile wallets
3. Direct blockchain transfer

USDC is sent directly from customer wallet to merchant wallet on-chain. Key security features:

  • StablePay never holds funds
  • Transaction signed in customer's browser
  • No intermediary custody
  • Full blockchain transparency
4. Transaction confirmed

Payment is verified on blockchain and merchant is notified:

  • Transaction hash recorded
  • Webhook sent to merchant backend
  • Order status updated to paid
  • Customer receives confirmation
Non-custodial architecture explained

StablePay NEVER holds your funds. Here's why this matters:

  • No risk of StablePay being hacked for your funds
  • No regulatory custody requirements
  • Payments arrive instantly in your wallet
  • You maintain full control at all times
  • We only provide the payment interface

Supported Networks

Ethereum (L1 + L2)

Most secure and battle-tested blockchain. Support for mainnet and testnets:

  • Ethereum Mainnet (production)
  • Sepolia Testnet (testing)
  • Full ERC-20 token support
  • MetaMask native integration
Base & Optimism (L2)

Low-cost Optimistic Rollups with Ethereum security:

  • Base Mainnet & Sepolia
  • Optimism Mainnet
  • ~100x cheaper than Ethereum L1
  • 1-2 second confirmation times
Polygon & Arbitrum

High-throughput scaling solutions:

  • Polygon (Mainnet & Mumbai testnet)
  • Arbitrum (Mainnet & Sepolia)
  • Sub-cent transaction fees
  • Near-instant finality
Solana

Ultra-fast payments with sub-second finality:

  • Solana Mainnet & Devnet
  • 400ms block times
  • $0.00025 avg transaction cost
  • Phantom wallet integration

Token Standards

ERC-20 tokens

Industry-standard tokens on EVM chains:

  • USDC (USD Coin by Circle)
  • USDT (Tether)
  • EURC (Euro Coin by Circle)
  • All audited and widely adopted
SPL tokens on Solana

Solana Program Library standard. Currently supporting USDC with more tokens coming soon.

Security-first approach

We only support battle-tested tokens:

  • No custom or unaudited tokens
  • Only tokens by Circle and Tether
  • Multi-billion dollar market caps
  • Years of proven security

Transaction Verification

On-chain verification

Every payment is verified directly on the blockchain. No off-chain trust required - math and cryptography guarantee payment authenticity.

Real-time monitoring

We monitor blockchain nodes 24/7 to detect and confirm transactions instantly. Webhooks fire within seconds of confirmation.

Public transparency

All transaction hashes are publicly visible:

  • Verify on Etherscan, Basescan, etc
  • Immutable proof of payment
  • Full audit trail
  • No hidden transactions

Access Control

Role-based access control

Granular permissions system. Team members only access what they need - developers can't access production databases, support can't modify code.

Multi-factor authentication

MFA required for all team accounts. Hardware security keys (YubiKey) required for admin access. No exceptions.

API key rotation

All API keys and secrets automatically rotated every 90 days. Zero-downtime rotation with overlapping validity periods.

Least privilege principle

Every user and service has minimum permissions needed. Regular access reviews to remove unused permissions.

Monitoring & Logging

24/7 system monitoring

Round-the-clock infrastructure monitoring across all systems:

  • Application performance metrics
  • Database query performance
  • Blockchain node health
  • Network latency tracking
Real-time alerts

Instant notifications for errors, slowdowns, or anomalies. On-call engineers paged immediately for critical issues.

Comprehensive audit logs

Every action logged with timestamp, user, IP address, and context. 90-day retention for compliance and debugging.

Anomaly detection

Machine learning models detect unusual patterns - sudden traffic spikes, unusual API usage, or potential attacks.

Incident Response

Documented response plan

Detailed playbooks for every scenario - data breaches, DDoS attacks, infrastructure failures. Regularly tested and updated.

24-hour critical response

Critical security issues addressed within 24 hours. On-call rotation ensures always-available response team in NYC timezone.

Post-incident analysis

Thorough root cause analysis after every incident. Public postmortems for issues affecting merchants. Preventive measures implemented.

Customer notifications

Transparent communication during incidents. Email, dashboard alerts, and status page updates keep merchants informed.

Payment Security

Instant settlement

No chargebacks, ever. Crypto payments are final once confirmed:

  • Funds arrive in seconds, not days
  • No 2-4% chargeback fraud loss
  • No payment disputes or reversals
  • Merchant keeps 100% of revenue
Blockchain verification

Every transaction is mathematically verified on-chain. No fake payments, no double-spends, no fraud.

No payment reversals

Crypto's biggest advantage - payments can't be reversed by banks or payment processors. You're in control.

Automatic fraud detection

Machine learning monitors transaction patterns. Suspicious activity flagged instantly for merchant review.

Business Continuity

99.9% uptime SLA

Less than 9 hours of downtime per year. Financial penalties if we miss SLA targets. Your payments stay online.

Multi-region infrastructure

Deployed across multiple data centers worldwide. If one region fails, traffic automatically routes to healthy regions.

Automated failover

Health checks every 10 seconds. Automatic failover to backup systems in under 30 seconds. Zero manual intervention.

Real-time status page

Live system status at status.wetakestables.shop. Subscribe for incident notifications and maintenance windows.

Refund Management

Built-in refund system

Issue refunds directly from your dashboard. Connect your wallet once, refund with one click. Full history and tracking.

Batch refund support

Process multiple refunds in one transaction using Multicall3:

  • 60-85% gas savings vs individual refunds
  • Refund hundreds of customers at once
  • Single blockchain transaction
  • Available on all EVM chains
Full audit trail

Every refund logged with reason, amount, timestamp, and transaction hash. Export for accounting and compliance.

Merchant-controlled policies

You set refund policies. Full refunds, partial refunds, or no refunds - your business, your rules.

Open Source

Client-side SDK on GitHub

Full source code available for inspection:

  • Payment modal implementation
  • Wallet connection logic
  • Transaction signing code
  • Community contributions welcome
Public API documentation

Complete API docs with code examples in multiple languages. Try all endpoints in interactive playground before integrating.

No hidden fees

Simple pricing: 1% per transaction (volume discounts to 0.3%). No setup fees, no monthly fees, no surprise charges. What you see is what you pay.

Clear pricing structure

Transparent pricing, always:

  • 1% transaction fee (0.3% for high volume)
  • No monthly minimums
  • No integration fees
  • Volume discounts available

Security Disclosure

Responsible disclosure program

Found a security issue? Report it privately to security@wetakestables.shop. We'll acknowledge within 24 hours and keep you updated throughout the fix process.

Bug bounty program

Launching Q4 2025. Rewards up to $10,000 for critical vulnerabilities. Help us build the most secure crypto payment platform.

Public security advisories

All security issues published on GitHub after fix deployment. Full timeline, impact assessment, and remediation steps disclosed.

Regular security updates

Monthly security newsletter with platform updates, dependency patches, and industry security news. Subscribe in your dashboard.

Report Security Issues

If you discover a security vulnerability, please email us at:

security@wetakestables.shop

Include: detailed description, steps to reproduce, potential impact, and your contact info. We respond within 24 hours.

Ready to Get Started?

Join hundreds of merchants accepting crypto payments with StablePay

What you get:

  • Live in 5 minutes
  • Starting at 1% per transaction
  • Multi-chain support
  • Built-in refunds
  • Real-time webhooks
  • Free analytics dashboard