Your Security, Our Priority

Security at Every Layer

From the moment you sign up to the second crypto lands in your wallet, PaySwapr applies layered protections — escrow, encryption, and verification — so you can trade with confidence.

Every
Trade held in encrypted escrow
AES-256
Wallet seed encryption
2FA
Admin access protection
24h
Dispute response target

Escrow Protection

When a trade starts, crypto is locked in escrow before the buyer sends payment. The funds can only move when both parties agree — or when our dispute team intervenes.

Crypto locked before buyer sends payment
Seller cannot cancel once crypto is escrowed
Dispute team can override on verified fraud

Transaction PIN

Every sensitive action — releasing escrow, withdrawing funds, changing your password — requires your transaction PIN. This creates a second authentication layer beyond your login password.

Required for all fund movements
Stored as bcrypt hash — never in plaintext
Protected against brute-force attacks

Encrypted Wallet Seed Phrases

Wallet seed phrases are encrypted before they are ever stored, under keys derived from your own PIN and platform-held secrets. Even if the database were compromised, seed phrases would remain unreadable.

Encrypted at rest — never stored in plaintext
PIN required to export seed phrase
Backed by institutional-grade blockchain infrastructure

KYC Identity Verification

KYC is optional for basic trading but required to access higher limits. Verified users build a more trusted profile and are less likely to be involved in fraud — protecting the entire community.

Government ID + selfie verification
Tiered limits for unverified / verified traders
KYC badge shown on public profile

Full Audit Logging

Every action on the platform — user and admin — is recorded and cannot be silently edited or removed. Security-relevant events are reviewed, so every decision is traceable and accountable.

Login activity recorded on every sign-in
Admin actions fully attributed
Append-only record — no silent edits or deletes
Users can view their own login activity

Two-Factor Authentication

Admin accounts require 2FA (TOTP) for login. Users can enable 2FA on their accounts for an extra layer of protection against account takeover.

Mandatory for all admin users
Google Authenticator / any TOTP app

Private Trade Chat

Trade chat messages are transmitted over HTTPS and stored server-side. Conversations are scoped strictly to the trade participants and the dispute team — no third parties can read them.

Scoped to trade participants only
Real-time encrypted connection

Responsible Disclosure

Found a security vulnerability? We welcome good-faith research and will not pursue legal action against you for testing that follows our disclosure policy. Read the scope, rules of engagement and our response commitments before you begin.

Read the Vulnerability Disclosure Policy

Report a Vulnerability
Report a Bug

So we can follow up if we need more detail.