TRUST & COMPLIANCE

Compliant by architecture

Most companies comply by adding controls around the data they hoard. We comply by never holding it: no stored photos, no custody of funds, no customer data on our servers — every instant cash payment settles directly between banks. What does not exist cannot be breached, subpoenaed or sold.

SOC 2 TYPE II BIPA · CCPA · GDPR · LGPD BSA / AML · OFAC NON-CUSTODIAL
WHAT WE ARE — AND WHAT WE ARE NOT

A rail, not a wallet

rostopay is non-custodial payment initiation infrastructure. We are not a bank, not a wallet with custody, not a data broker. We provide the rail for the parties to communicate — the value and the data never stop with us.

No custody of funds
Payments settle directly between the buyer's bank and the merchant's bank over RTP, Fedwire and A2A rails operated by licensed partner banks and money transmitters. Money never touches a rostopay account — there is no float, no omnibus wallet, no commingling.
No custody of data
Your facewallet lives with you. Identity, addresses and bank links are encrypted, sharded and controlled by the user — merchants receive attestations and trackable codes, never raw data. Nothing sits on our servers to be leaked.
No stored biometrics
No photo or video of your face is ever captured into storage. Enrollment produces an irreversible encrypted template on your device — it cannot be reversed into an image, by us or anyone else.
BIOMETRIC PRIVACY LAW

Built for the strictest biometric statutes in the country

U.S. biometric laws punish companies that collect and store biometric identifiers without consent. Our answer is structural: explicit consent at enrollment, no server-side storage, and instant deletion rights.

BIPA
Illinois Biometric Information Privacy Act (740 ILCS 14)
BIPA requires written consent, retention schedules and destruction of biometric identifiers. rostopay collects the template only with explicit informed consent, never sells or profits from biometric data, stores nothing server-side, and deletion at facewallet.rostopay.com is immediate and irreversible.
CUBI
Texas Capture or Use of Biometric Identifier Act (Bus. & Com. Code §503.001)
CUBI restricts capturing biometric identifiers for a commercial purpose without notice and consent. Enrollment is opt-in with clear notice; identifiers are never sold, leased or disclosed — they never leave the user’s device as reversible data.
WA HB 1493 / MHMD
Washington biometric & My Health My Data Acts
Washington requires notice, consent and purpose limitation for biometric enrollment. Biovital signals are processed transiently on-device for liveness only — never retained, never treated as a commercial asset.
CCPA / CPRA
California Consumer Privacy Act & Privacy Rights Act
Biometric information is "sensitive personal information" under CPRA. We honor access, deletion and limit-use rights by default — and because we store nothing, a deletion request has nothing to chase. No sale, no sharing, no dark patterns.
GLOBAL PRIVACY

GDPR and LGPD ready

For international users and partners, the same architecture satisfies the world’s strongest privacy regimes.

GDPR
EU General Data Protection Regulation (Art. 9 — biometric data)
Biometric data is a special category under Article 9, processable only with explicit consent. rostopay applies privacy-by-design (Art. 25): on-device processing, data minimization, purpose limitation, and the right to erasure executed instantly.
LGPD
Lei Geral de Proteção de Dados (Brazil, Law 13.709/2018)
LGPD treats biometrics as sensitive data (Art. 5, II) requiring specific consent (Art. 11). Our consent flow, minimization and user-held storage model map one-to-one to LGPD’s requirements — with the user as the effective controller of their own vault.
FINANCIAL REGULATION

Bank-grade rules, without holding a dollar

Money movement is executed by licensed, supervised institutions. rostopay initiates; regulated partners settle.

BSA / AML
Bank Secrecy Act & Anti-Money-Laundering program
Every user passes KYC at enrollment with liveness-proofed identity; transactions are screened against OFAC sanctions and watchlists with ongoing monitoring. Suspicious-activity escalation follows FinCEN guidance through our partner institutions.
KYC / AML / PEP
Real-time screening by design — 195+ countries
Identity, sanctions, watchlist and PEP (politically exposed persons) screening run in real time at enrollment and continuously after, covering 195+ countries and territories — adverse media included. Compliance is a property of the flow, not an afterthought.
ID VERIFICATION
AI document verification — OCR + MRZ, by design
Government IDs are verified with AI-powered OCR and MRZ (machine-readable zone) parsing, cross-checked against the live face with biometric matching and anti-tamper forensics — passports, driver licenses and national IDs from 195+ countries.
313 DATA SOURCES
313 verification connections worldwide
Identity attestations are corroborated against 313 external API connections worldwide — government registries, credit bureaus, telco and utility databases, sanctions lists and fraud consortiums — resolved in real time at enrollment.
NMLS
Licensed money transmission
Transfers are performed by licensed money transmitters and partner banks registered in NMLS, supervised state by state — coverage in all 50 states. rostopay itself never transmits or holds value.
FDIC
FDIC-insured partner banks
Customer funds only ever sit in the customer’s own bank and the merchant’s own bank — insured depository institutions, Member FDIC. There is no rostopay balance to insure because there is no rostopay balance.
OPEN FINANCE
Open finance compliance — provided by Plaid, 11,000+ banks
Bank connectivity and account authorization run on Plaid’s regulated open-finance infrastructure, covering 11,000+ U.S. financial institutions — consent-based access under Section 1033 principles, with credentials never touching rostopay.
GLBA
Gramm-Leach-Bliley Act — financial privacy & safeguards
Financial data crossing the rail is protected under GLBA-grade safeguards: encryption, access controls and vendor oversight — with the shortest possible data lifecycle, since nothing is retained.
Reg E / Nacha / RTP rules
Consumer transfer protections
A2A transfers follow the operating rules of the underlying rail — Nacha for ACH, TCH RTP rules, FedNow service rules — including error-resolution procedures handled with our partner institutions.
FINRA / SEC
Not applicable — by design
rostopay offers no securities, investments, yield or credit. We are payment initiation infrastructure, not a broker-dealer or investment adviser — so FINRA and SEC registration regimes do not attach.
CYBERSECURITY & INFRASTRUCTURE

Audited like a bank, engineered like a fortress

Independent audits and layered cryptography protect the rail itself — the only thing we actually run.

SOC 2 TYPE II
Independent controls audit
Our infrastructure is audited annually against the AICPA Trust Services Criteria — security, availability, confidentiality — with continuous evidence collection between audits.
E2E CRYPTOGRAPHY
Sharded, end-to-end encryption
Templates and attestations are protected with strong end-to-end cryptography and split into three shards, so no single party — including rostopay — can reconstruct them.
PCI DSS
Out of scope — no card data
We process zero PANs: no card numbers exist anywhere in the flow. The entire class of card-data breaches is structurally impossible on this rail.
NIST CSF
Framework-aligned operations
Security operations follow the NIST Cybersecurity Framework: continuous monitoring, least-privilege access, incident response drills and third-party penetration testing.
LIVENESS & ANTI-DEEPFAKE
Biovital verification
Every scan is checked for live pulse and micro-movement signals with anti-deepfake detection — photos, videos, masks and synthetic media are rejected on-device.
PUBLIC VERIFIABILITY
Proof by hash
Every transaction carries a Sieve ID and cryptographic proof hash, publicly checkable at verify.rostopay.com — auditability without exposing any personal data.

Questions from your compliance team?

We share audit reports, DPAs and architecture reviews under NDA.

compliance@rostopay.com Privacy Policy

Explore rostopay

Online cash payment, biometric checkout and pay-with-your-face resources.