Wallet & Payments

Web3 ownership, without the Web3 homework

Keys are generated and held on the user's device. Onboarding runs on biometrics or passkeys. Network fees can be sponsored. No seed-phrase handling, no browser extension, and no requirement to buy a native token before making an ordinary purchase.

Consumer experience

One account, every form of value

  • Onboarding with device biometrics or passkeys, with clear wallet and privacy disclosures.
  • No routine need to hold SOL purely for fees, where sponsored transactions are available.
  • One view across supported digital assets, store credit, rewards, offers, and transaction history.
  • Rail choice at checkout, with fees, exchange rate, settlement type, and reversibility disclosed before authorisation.
  • Encrypted recovery, and elevated authentication for transfers, recovery downloads, and refunds.

Multi-rail checkout

Six ways to pay, each with its trade-offs stated

Fees, exchange rate, settlement type, and reversibility are disclosed before the customer authorises anything — including where a rail is worse for them.

Digital dollars

USDC on Solana

A fast digital-dollar experience with predictable denomination.

Operational consideration

Requires wallet liquidity, blockchain monitoring, sanctions controls, a conversion partner, and a clear finality and refund policy.

Security control model

Non-custodial is a key-management claim, not a blanket one

SYNC avoids custody of user private keys while still operating ledgers, sponsoring fees, processing personal data, and integrating custodial fiat providers. Each of those responsibilities has its own control owner and legal classification.

Keys never leave the device

Private keys are generated and retained on the user device. Backend wallet association is proven by a signed, single-use challenge — the server never holds the key.

Hardware-backed storage

Secure enclave storage where supported, with biometric or passkey authorisation required for sensitive operations.

Zero-knowledge recovery

Recovery material is encrypted client-side with AES-GCM under a password-derived key before backup. No plaintext recovery phrase is ever transmitted.

Short-lived sessions

Short-lived access tokens, rotating hashed refresh tokens, session revocation, device trust controls, and risk-based step-up claims.

Second factor & audit trail

TOTP two-factor authentication, recovery codes, IP and device signals, rate limiting, and an immutable security event trail.

Replay-resistant settlement

Authenticated webhooks and idempotent transaction processing complete before any ledger credit is applied.

Put the wallet in your own app

The SDK ships prebuilt components for wallet, checkout, offers, loyalty, and portfolio — embedded in your brand experience, not a separate destination.