Security & non-custodial model

BramaPay is payment tooling — not a custodial wallet. Your keys, your settlement addresses.

How money moves

Customer payments and platform fees never share the same path. That separation is the core of the model.

01

Payment funds

Payer → your registered wallet on-chain. BramaPay watches the chain; it does not hold the funds.

02

Platform fees

Charged from a service balance you top up separately. Invoice creation can pause if that balance cannot cover fees.

No payment custody

Customer funds are sent on-chain to merchant-registered addresses. BramaPay does not intermediate those transfers.

Separated fee balance

Platform fees are charged from a service balance you top up. Payment wallets and fee accounting stay distinct.

Signed webhooks

Delivery uses an HMAC-signed envelope. Verify the signature and eventId before fulfilling an order.

Project isolation

API keys, wallets, webhooks, and invoices are scoped to a project so environments stay separated.

What you should still verify

  1. 01

    Fulfill only from verified webhooks or authenticated invoice status — never from a success redirect alone.

  2. 02

    Store API secrets server-side and rotate them if exposed.

  3. 03

    Allowlist exact return domains for checkout redirects.