Security
Security as operational discipline.
MonetLayer security language stays precise: no certifications, audits, SLAs, or formal programs are claimed here beyond what the current product evidence supports.
Also see the settlement proof and settlement evidence guide.
Current controls
- Customer-signed transactions for demonstrated collections
- Independent transaction receipt verification before reconciliation
- Historical replay protection in the demonstrated proof
- Idempotent duplicate processing against the same payment evidence
- No customer private-key custody on the MonetLayer side
- No merchant or customer fund custody by MonetLayer
Architecture boundaries
- MonetLayer does not custody merchant funds.
- MonetLayer does not store customer private keys.
- Wallet interaction remains on the customer or payment-provider side.
- MonetLayer verifies settlement evidence and updates billing state.
- Provider execution and MonetLayer revenue operations are separate layers.
Operational practices
- Tenant-scoped product access patterns
- Least-privilege operational posture for infrastructure access
- Webhook delivery as durable merchant notification history
- Honest public status labeling for testnet versus roadmap capabilities
Responsible disclosure
Report security issues to security@monetlayer.com. Preferred language: English. Policy page: /security. Canonical security.txt: https://www.monetlayer.com/.well-known/security.txt.
security.txt expires: 2027-08-01T00:00:00.000Z
Roadmap
- Formal third-party audit publication
- Expanded public rate-limit and webhook-signing documentation
- Additional provider integrations beyond the current Direct Base testnet model
Request early access