pvium Trust & Security
Security at Pvium
How Pvium protects your funds, your account, and your data — starting with an architecture where we never hold your money.
Non-custodial by design
Pvium never holds, controls, or has access to your funds. Wallet balances stay in wallets you control, and money can only move when you sign. There is no Pvium bank account holding your money, no float, and no Pvium-controlled key that could move your assets.
This is not a policy promise — it is how the platform is built. Because Pvium cannot move funds — from your wallet or from a payout contract — a compromise of Pvium systems cannot drain them.
Smart contracts for scheduled & pooled payouts
Instant payouts settle directly from your wallet to the recipient. Scheduled and pooled payouts work differently: when you fund one, the funds are locked in a payout smart contract on-chain — not in a Pvium-controlled account.
- The contract only releases funds to the recipients named in the batch you signed, on the terms you signed
- Pvium cannot redirect, withdraw, or repurpose funds held by the contract
- Unclaimed or cancelled funds are returned to the paying wallet under the contract’s rules — never to Pvium
- Funds held by the contract are visible and verifiable on-chain at all times
Wallet infrastructure
Wallets are created and secured through dedicated third-party wallet infrastructure (Privy). Private keys are accessible only to you:
- Pvium cannot access, export, reset, or recover private keys
- Signing happens on your side — Pvium only prepares the payment for your approval
- Embedded wallets support additional wallet-level MFA for sensitive operations
Account protection
Your Pvium account supports two-factor authentication using an authenticator app (TOTP) or SMS. Organization access is scoped: API keys and dashboard sessions only reach the organization they were issued for.
Data protection
All traffic between your browser, our APIs, and our infrastructure is encrypted in transit with TLS. Data is encrypted at rest.
Sensitive documents — such as collected W-9 and W-8 tax forms — are stored encrypted with per-document encryption keys, so they are unreadable without a key that is never stored alongside the data.
API & integration security
- API keys are issued per organization and can be revoked at any time
- Requests are authorized against the owning organization on every call
- Webhooks let your systems verify payment state instead of trusting client-side data
Payment integrity
Every payout batch is signed by you and verifiable on-chain. Pvium keeps a tamper-evident record of each payment — who was paid, when, from which batch, and under which compliance checks — so the history of a payment can always be proven, not just asserted.
Reporting a vulnerability
If you believe you have found a security issue in Pvium, please report it to support@pvium.com. We ask that you give us a reasonable opportunity to investigate and remediate before public disclosure. We do not take legal action against good-faith security research.
Contact
Fero Technologies, LLC
8735 Dunwoody Place, Ste N, Atlanta, GA 30350, United States
Email: support@pvium.com