Security

Trust isn't claimed.
It's engineered.

A payments company asks people to hand over the thing they work hardest for. So trust isn't a word on a page here — it's a property of the system itself. Nothing about your money depends on taking our word for it.

And where a standard is something we've built toward rather than been formally certified for, we say so. The cross-border corridor is still being built — we label it as such, not dressed up as a live product.

Built around the rules that govern Turkish finance
BDDKMASAKKVKKPCI DSS

Biometric by default

Funds and sensitive actions sit behind biometric confirmation on the device itself. Nothing moves without you.

Regulated custody

Every balance is held under regulated custody, with strong encryption at rest and in transit. Not our word — the system's.

Zero-trust by design

No part of the system implicitly trusts another, so a single compromised point can't cascade. Attacks are contained, detected, stopped early.

Your data stays in Türkiye

Held in-country, governed by Turkish law. Never sold, never quietly shared. We collect only what the service genuinely requires.

Security architecture & transactional safeguards

Engineered so that trust never rests on a single point.

DevPay's model is anchored on the absolute decoupling of core systems from adversarial environments — paired with cryptographic, identity, and ledger safeguards that each assume the others could fail.

Infrastructure

Decoupled from adversarial ground

Core systems run entirely on external cloud networks in compliant jurisdictions — Türkiye and the European Economic Area. There is no local server footprint for a hostile state actor to seize or compromise.

Identity records

Sensitive data held off-jurisdiction

Biometric data, national-ID verification hashes, and personal profiles are stored outside the domestic jurisdiction under GDPR-equivalent encryption, insulating them from forced extrajudicial extraction.

Cryptographic control

Keys no single party can turn

Multi-signature protocols and jurisdictionally distributed shards split time-locked cryptographic keys across separate entities. No single administrative node can unilaterally decrypt the user database.

Onboarding

Verified humans, not text fields

Onboarding forces device fingerprinting, liveness detection, and SIM-metadata checks — binding a user's digital signature to their real legal identity instead of trusting typed-in details.

Access integrity

True location, enforced

IP-based geolocation and hardware tracking neutralize evasion attempts, blocking unauthorized VPNs and routing proxies so the app validates the client terminal's genuine jurisdiction.

Ledger screening

Every deposit screened on arrival

Continuous integration with institutional analytics providers — Chainalysis and TRM Labs — screens every incoming stablecoin or digital-asset deposit against illicit-source and sanctions risk in real time.

Distributed key custody

A decryption requires a quorum of time-locked shards held by separate entities across jurisdictions. One node alone can never expose the database.

Shard A

Türkiye

+

Shard B

EEA — Frankfurt

+

Shard C

EEA — Amsterdam

Quorum required to decrypt

Multi-layer identity binding

Onboarding stacks technical signals — each layer must pass before a verified identity is issued. Evasion via VPNs or spoofed inputs is rejected.

1Device fingerprint
2Liveness detection
3SIM metadata check
4Geolocation validation

Real-time ledger screening

Every incoming digital asset is automatically screened against illicit-source and sanctions risk before it ever settles to a user balance.

ChainalysisTRM Labs