Security

Secure global payments without adding custody risk.

Launch with clear security boundaries: payer authorization in wallet flow, merchant-direct settlement, and signed backend events your team can verify.

Non-custodial settlementWebhook signaturesAPI key rotationTransparent boundaries
Create Merchant Account

Security control console

Current controls only

Verified flow

Custody

Private keys remain with merchant wallets

Webhook

HMAC signature validation supported

API key

Regeneration available in dashboard

Orders

Duplicate order IDs rejected per merchant

Boundary mapNo custody

Payer wallet

Authorizes payment

Trezalink

Creates session and signs events

Merchant wallet

Receives settlement

Platform boundary: orchestration, not custody
Security snapshot

Protection you can scan in five seconds.

These are active platform controls available in current product flows.

Custody model

Wallet-direct settlement

Merchant funds are not held by Trezalink.

Webhook integrity

HMAC signature support

Verify event origin with webhook secrets.

Credential hygiene

API key rotation

Regenerate merchant API keys from dashboard.

Order safety

Duplicate order protection

Reused order IDs are rejected per merchant.

Control boundaries

Merchant control stays explicit at every sensitive edge.

Trezalink coordinates checkout sessions, settlement records, and signed events while merchant teams keep ownership of wallet custody and backend secret handling.

Payer authorization happens in wallet flow, not through shared platform custody.

Settlement goes directly to merchant wallet after payment confirmation.

Operational events can be validated via webhook signatures and logs.

Security boundaries are explicit between platform controls and merchant secrets.

Start secure onboarding
Shared responsibility

Clear ownership for each secret.

API key

Merchant: Store securely and rotate on schedule.

Trezalink: Provide key regeneration in the dashboard.

Webhook secret

Merchant: Validate incoming signatures in backend handlers.

Trezalink: Sign payloads and expose delivery/webhook logs.

Wallet key

Merchant: Maintain wallet custody and signing control.

Trezalink: Never request or store private keys.

Operational readiness

Security controls your ops and dev teams can reason about.

Keep the checkout surface simple while preserving verification, credential hygiene, status context, and reconciliation details around every payment flow.

Read security docs

Private-key boundary

Merchant wallet keys stay outside Trezalink systems and remain under merchant wallet control.

Webhook verification

Backend events can be validated with HMAC signatures before fulfillment logic runs.

Credential rotation

Merchant API credentials can be regenerated from the dashboard when teams rotate secrets.

Duplicate order protection

Reused order IDs are blocked per merchant to reduce accidental duplicate checkout state.

Status visibility

Public status and product reporting surfaces help teams separate incidents from integration issues.

Finance-ready logs

Payment records, webhook logs, and fee details support reconciliation after settlement.

Security FAQ

Answers before go-live.

Does Trezalink ever access merchant private keys?

No. Merchant private keys remain with the wallet provider and are never handled by Trezalink.

How do we verify webhook authenticity?

Use your webhook secret to validate the X-Trezalink-Signature HMAC value on every incoming event.

How is settlement finalized?

Payments settle after on-chain confirmation and are recorded with fee and net details for reconciliation.

Where can teams monitor reliability?

Status and operational transparency are available through the public status and product reporting surfaces.

Launch securely

Launch Solana payments with boundaries your team can explain.

Start accepting global payments with non-custodial settlement, signed events, and clear ownership for merchant secrets.

Create Merchant Account