Plutus Crypto

Risk and compliance

The boring part, done properly

Crypto acceptance only works if your bank, your auditor and your acquirer stay comfortable with it. Everything on this page exists to keep them that way.

100%of incoming transactions screened
0chargebacks, by design
0card numbers in your scope
24 hwebhook retry window

Money in

Screened before it is credited

A payment address is unique to a payment and retired after it. Whatever arrives is checked before it counts.

Sanctions and risk scoring

Every incoming transaction is traced against sanctions lists and a risk model that looks at where the funds came from, before it is credited to your balance. High risk funds are held for review, not passed through.

Travel Rule

Where a transfer crosses the threshold that requires originator and beneficiary information to travel with it, we exchange that information with the counterparty service. You do not have to build anything for this.

Merchant onboarding

We verify who you are and what you sell before you take a payment. It takes a few days, it is the reason banks accept our settlements, and it is the reason your account is worth something.

Finality

No chargebacks, no reserves

A confirmed blockchain payment cannot be reversed by the payer, the payer's bank or us. That removes the dispute window, the dispute fees and the rolling reserve that card acquirers hold against merchants in higher risk sectors.

Confirmation depth per asset

We wait for a number of confirmations that makes a reorganisation of the chain economically absurd before we call a payment final: two on Bitcoin, twelve on Ethereum, one on the XRP Ledger, and so on. You can release goods earlier for small tickets, on first sight in the mempool, and the dashboard tells you which payments were released that way.

Under and overpayment

Wallets round, fees get deducted at the wrong end, customers fat finger a digit. When less arrives than quoted, the payment is held with the shortfall shown and you decide: accept, ask for the rest, or refund. When more arrives, the surplus is held for you without a fee.

Your account

Keys, people and the record

Scoped API keys

Separate keys for sandbox and production, each scoped to payments, payouts or read only. Rotate a key from the dashboard and the old one stops working at once. Optional IP allow list per key.

Signed webhooks

Every delivery carries a timestamp and an HMAC signature over the raw body. Verify it in three lines and reject anything we did not send. Failed deliveries retry for 24 hours and any event can be replayed.

Roles and two factor

Finance sees money, support sees orders, developers see keys. Two factor sign in is on for every user, and payouts above a threshold you set need a second approver.

Audit trail

Every action in the dashboard, every key used, every payout approved is written to a log you can filter and export. When your auditor asks who did what, the answer is a download.

Custody

Incoming funds are converted at settlement and held in segregated accounts until they are paid to you. Stablecoin floats you choose to keep are held in wallets with keys split across hardware modules, never on a laptop.

No card data

Nothing that touches a card network touches us. There is no PAN to protect, no PCI scope added to your stack, and no card data breach possible on this channel.

Reporting a vulnerability

If you believe you have found a security issue in our platform or this website, write to info@plutuscrypto.com with the subject line Security report. We answer within two business days, we do not take legal action against good faith research, and we credit reporters who want to be credited.

Questions your bank will ask

We have answered them before. Tell us who you bank with and we will send you the pack they usually want to see.