Security

The safest money is money we never hold.

Penni is non-custodial: payments move from the payer's wallet to yours. That removes the biggest risk in payments before we write a line of code. Here's how we handle the rest.

Payments

Settle only what pays you.

The facilitator signs nothing on your behalf. It submits transfers the payer signed, and only after these checks.

  1. No custodyPenni has no access to your wallets and no contract holds your funds. Our fee-payer wallets on Base and Solana only pay network fees; on Cardano we hold no key at all.
  2. Recipient checkA payment is only settled if it goes to the wallet set for that site, in a token the site accepts.
  3. Exact amounts, counted onceThe exact scheme transfers precisely the signed amount within a validity window. A payment can't be replayed: a one-time nonce on Base, a consumed UTXO on Cardano, and a duplicate check on Solana.
  4. Known tokensBuilt-in tokens are Circle's EURC and USDC on Base and Solana, and USDM on Cardano, from the official sources.
Accounts & keys

Built to limit the blast radius.

  1. No passwordsYou sign in with a one-time link by email or a passkey (Touch ID, Face ID, Windows Hello, security keys), so there are no passwords to leak or reuse. Optional two-factor authentication with an authenticator app, with recovery codes.
  2. Hashed and encrypted secretsSite API keys, session tokens and sign-in links are stored only as hashes. Authenticator and webhook secrets are encrypted. A database leak doesn't reveal them.
  3. Scoped site keysA key works for one site only, can be revoked at any time, and can only settle payments to that site's wallet.
  4. RolesOwners, admins and viewers. Viewers can see numbers but change nothing.
  5. Sessions you controlSee every signed-in device, sign out one or all, and get an email when a new device signs in. Sessions end after 14 days without use.
  6. Abuse protectionRate limits on sign-in, same-origin checks against cross-site requests, a strict content security policy, HTTP-only session cookies.
  7. Signed card paymentsCard top-ups are credited only on Stripe events with a valid signature. We never see card numbers.
  8. Signed webhooks to youEvery webhook we send is signed with your endpoint's secret (HMAC-SHA256). We only call https addresses and refuse internal network addresses.
Infrastructure

European, and minimal.

  1. EU hostingThe dashboard, facilitator and database run on Hetzner servers in the European Union.
  2. TLS everywhereAll traffic is encrypted with automatically renewed certificates. The facilitator itself is not reachable from the internet; only the authenticated gateway is.
  3. Open-source coreSettlement runs on open-source code: x402-rs for Base and Solana, and the official x402 package for Cardano, at pinned versions.
Disclosure

Found something?

We'd love to hear about it before anyone else does.

Email [email protected] with the details and steps to reproduce. We will confirm receipt within two working days, keep you updated, and credit you when the fix ships, if you like.

Please don't access other people's data, disrupt the service or move funds while testing, and give us reasonable time to fix the issue before you go public. If you follow these rules, we won't take legal action against you.