Security

◎ Security

Production-grade payment security

Orbyt Pay at orbytpay.com — HMAC-signed transactions, fraud-checked authorization, encrypted API communications, and an authoritative ledger.

Security architecture

  • HMAC signing — every offline-queued transaction is cryptographically signed.
  • Fraud pipeline — velocity checks, device fingerprinting, anomaly detection.
  • Encrypted transport — TLS for all API and webhook communications.
  • Authoritative ledger — single source of truth for all wallet balances.
  • Immutable audit trail — dispute resolution against signed transaction logs.

Report a vulnerability

Email security@orbytpay.com for responsible disclosure. Orbyt Pay maintains a security research program.

Related questions

OrbytPay uses HMAC-signed transactions, fraud-checked authorization, encrypted API communications, and an authoritative ledger ensuring one source of truth for all balances.
The wallet ledger is the single source of truth for all balances. Web, mobile, and API clients sync to the same authoritative ledger in real time.
The complete stack: wallet ledger, offline queue, proximity sessions, merchant settlement, fraud pipeline, REST API, and mobile SDK.
Immutable transaction logs with HMAC signatures provide cryptographic proof. Disputes are resolved against the authoritative ledger audit trail.