Least privilege
Production credentials and API access should be limited to the scopes required for each service.
PNECHE approaches financial software development with security, least-privilege access, separation of responsibilities and operational observability as core design principles.
Production credentials and API access should be limited to the scopes required for each service.
Sensitive credentials are intended to remain server-side and outside customer-facing applications.
Self-custody wallet recovery material is designed to remain under the customer's control.
Operational events and settlement records are designed to support reconciliation and investigation.
Skeypa is being built with the intention that regulated KYC and payment functions are performed through appropriately selected providers rather than recreated casually inside the product.
Skeypa is pre-launch. Security and compliance controls will continue to evolve through testing, provider review, legal advice and operational readiness work before any public production launch.