Skip to content

Security Overview

Security is the foundation of Pybara. Here’s how we protect your payments.

Pybara never holds customer funds. Payments go directly from customer to merchant.

The payment verification canister is a blackhole canister — immutable code that cannot be upgraded or modified.

The payment canister code is publicly verifiable on-chain. All payment transactions are recorded on the Internet Computer’s public ledgers and can be independently verified.

Every payment is verified on the Internet Computer blockchain. No centralized server can fake or modify transactions.

Transactions require consensus from multiple nodes in the subnet. No single point of failure.

All data served from IC canisters is cryptographically certified by the subnet.

Authentication uses Internet Identity — a decentralized, passwordless system using:

  • Biometric authentication (Face ID, Touch ID, Windows Hello)
  • Hardware security keys
  • No passwords to steal or leak

Wallets are non-custodial. Users control their own keys. Pybara cannot access user funds.

All smart contracts are publicly auditable and follow IC best practices.

Payment verification logic is immutable (blackhole canister). No upgrades, no changes.

Proper access controls prevent unauthorized operations.

Found a security issue? Please report it responsibly: