Wallet & Payments
Web3 ownership, without the Web3 homework
Keys are generated and held on the user's device. Onboarding runs on biometrics or passkeys. Network fees can be sponsored. No seed-phrase handling, no browser extension, and no requirement to buy a native token before making an ordinary purchase.
Consumer experience
One account, every form of value
- Onboarding with device biometrics or passkeys, with clear wallet and privacy disclosures.
- No routine need to hold SOL purely for fees, where sponsored transactions are available.
- One view across supported digital assets, store credit, rewards, offers, and transaction history.
- Rail choice at checkout, with fees, exchange rate, settlement type, and reversibility disclosed before authorisation.
- Encrypted recovery, and elevated authentication for transfers, recovery downloads, and refunds.
Multi-rail checkout
Six ways to pay, each with its trade-offs stated
Fees, exchange rate, settlement type, and reversibility are disclosed before the customer authorises anything — including where a rail is worse for them.
USDC on Solana
A fast digital-dollar experience with predictable denomination.
Requires wallet liquidity, blockchain monitoring, sanctions controls, a conversion partner, and a clear finality and refund policy.
Security control model
Non-custodial is a key-management claim, not a blanket one
SYNC avoids custody of user private keys while still operating ledgers, sponsoring fees, processing personal data, and integrating custodial fiat providers. Each of those responsibilities has its own control owner and legal classification.
Keys never leave the device
Private keys are generated and retained on the user device. Backend wallet association is proven by a signed, single-use challenge — the server never holds the key.
Hardware-backed storage
Secure enclave storage where supported, with biometric or passkey authorisation required for sensitive operations.
Zero-knowledge recovery
Recovery material is encrypted client-side with AES-GCM under a password-derived key before backup. No plaintext recovery phrase is ever transmitted.
Short-lived sessions
Short-lived access tokens, rotating hashed refresh tokens, session revocation, device trust controls, and risk-based step-up claims.
Second factor & audit trail
TOTP two-factor authentication, recovery codes, IP and device signals, rate limiting, and an immutable security event trail.
Replay-resistant settlement
Authenticated webhooks and idempotent transaction processing complete before any ledger credit is applied.
Put the wallet in your own app
The SDK ships prebuilt components for wallet, checkout, offers, loyalty, and portfolio — embedded in your brand experience, not a separate destination.