Security & non-custodial model
BramaPay is payment tooling — not a custodial wallet. Your keys, your settlement addresses.

How money moves
Customer payments and platform fees never share the same path. That separation is the core of the model.
01
Payment funds
Payer → your registered wallet on-chain. BramaPay watches the chain; it does not hold the funds.
02
Platform fees
Charged from a service balance you top up separately. Invoice creation can pause if that balance cannot cover fees.
No payment custody
Customer funds are sent on-chain to merchant-registered addresses. BramaPay does not intermediate those transfers.
Separated fee balance
Platform fees are charged from a service balance you top up. Payment wallets and fee accounting stay distinct.
Signed webhooks
Delivery uses an HMAC-signed envelope. Verify the signature and eventId before fulfilling an order.
Project isolation
API keys, wallets, webhooks, and invoices are scoped to a project so environments stay separated.
What you should still verify
- 01
Fulfill only from verified webhooks or authenticated invoice status — never from a success redirect alone.
- 02
Store API secrets server-side and rotate them if exposed.
- 03
Allowlist exact return domains for checkout redirects.