Trust Center · live posture

Heavy on the inside.
Transparent on the outside.

Paystack custodies funds. That is a high-trust posture. The Trust Center documents exactly how those funds are held, who can touch them, what compliance frameworks apply, and what we publish the day a problem is detected.

Current posture

Status board.

Verifier
operational
no open integrity alerts
Buffer
operational
releases on schedule
Ledger anchor
operational
last notarized 2d ago
Incident posture
operational
0 open, P99 < 120ms
Custody

FBO — for benefit of — accounts.

Your customers’ funds never commingle with Paystack’s operating capital. They sit in segregated For Benefit Of accounts at a partner bank, held in your customers’ names. If Paystack or Codelucent disappeared tomorrow, the FBO funds would not be part of the bankruptcy estate.

Pass-through insurance

Each end-beneficiary receives pass-through FDIC coverage up to the applicable limit. Documented quarterly in the ledger.

Daily attestation

Partner bank publishes a daily reconciliation hash. Our ledger includes it. Any drift between them alerts the Verifier.

No rehypothecation

Buffered funds are never lent, swept, or invested. They sit in cash until released or reversed.

Compliance

The frameworks we build against.

FrameworkScopeStatusEvidence
Nacha 2026 · Agentic Commerce RulesReasoning disclosure, reversal flow, counter-party verificationAlignedmapping doc available under NDA
SOC 2 Type IISecurity, Availability, ConfidentialityIn audit · window closes 2026-Q3report on request post-audit
OFAC · sanctions screeningCounter-parties screened on every initiateContinuousscreening log per-tenant
BSA / AMLKYB on tenants · transaction monitoringIn effectMLRO oversight · partner bank
PCI DSSN/A · Paystack does not process card railsOut of scope
Operational controls

What stops a bad day from becoming a bad quarter.

Read-only Verifier

The integrity checker has credentials that cannot move funds or mutate the ledger. It only raises incidents.

Four-eyes on release

Any operator-initiated release before the buffer elapses requires two distinct operator approvals, logged to the ledger.

Signed webhooks

Every state change event is signed. Public verification keys are published and rotated on a documented schedule.

Incident disclosure

Any Verifier-raised integrity alert appears publicly on this Trust Center within 60 minutes of page-out.

Backup cadence

Ledger snapshots are written continuously to three regions. Weekly root hashes anchored to a public notary.

Break-glass review

Annual red-team targets the Verifier and FBO reconciliation flow. Findings published in the next SOC2 window.

Documents & contact

Under NDA, the full binder.

Enterprise customers get the full SOC2 report, the Nacha mapping, the FBO structure diagram, and the incident postmortem archive. Request access and we’ll route you to the right person.