Products
Assets
Company
Transparency
Developers
Products
Assets
Company
Transparency
Developers
Security

Secured at every layer

Paxos operates as a regulated financial institution. We hold our signing hardware, code and team to the highest standards.

Paxos is an OCC-regulated national trust bank.

SOC 1 Type 2

Evaluates internal controls over asset custody, transaction execution, fiat/crypto transfers, and reserve reconciliations.

SOC 2 Type 2

Independent attestation evaluating security, processing integrity, and confidentiality criteria across architecture.

24x7 Security Ops

Our team monitors the platform continuously and responds rapidly, ensuring resilience.

Examined from every direction

Examined from every direction

Our enterprise information-security program covers security, availability, privacy, resilience, continuity, and incident response. It’s examined continuously. Independent auditors attest on a regular cycle, and leading independent security firms evaluate the platform, including penetration testing, red-team exercises, and third-party smart-contract audits.

We assume every control will be inspected, and we build so every claim holds up when it is.

Our enterprise information-security program covers security, availability, privacy, resilience, continuity, and incident response. It’s examined continuously. Independent auditors attest on a regular cycle, and leading independent security firms evaluate the platform, including penetration testing, red-team exercises, and third-party smart-contract audits.

We assume every control will be inspected, and we build so every claim holds up when it is.

No single point of failure

The platform runs on multi-region infrastructure with redundancy at every layer. When something breaks, it stays isolated, and the rest of the platform keeps running.

Multi-region by design

Infrastructure spans multiple regions with redundancy at every layer, backed by regular disaster recovery testing.

Always on watch

Live alerting and threat monitoring feed a security operations team that is on watch every hour of the year.

Ready to respond

Paxos has a documented incident-response program with defined severities, on-call teams, and retrospectives.

No one acts alone

Multi-party authorization protects asset movements, wallets, and changes across the platform.

Up to $1M for critical findings

Through our bug bounty program, researchers who uncover critical security vulnerabilities in the Paxos platform can earn up to $1,000,000 in USDG.

Get Started

Ready when your team is

Ready when
your team is

SOC reports and detailed security documentation are available under NDA, and our security team can join your review directly.

Whether you’re in early conversations or active RFP, we can help you explore the best regulatory model to support your business.

FAQs

Is Paxos SOC 2 compliant?

How does Paxos protect customer assets?

Does Paxos have a bug bounty program?

How does Paxos handle personal data?

How does Paxos secure its own software and operations?

How do I report a scam or someone impersonating Paxos?

Explore the Paxos Platform

Custody & Wallets

Where assets sit, how they're protected, and the controls on every movement.

Learn More

Regulatory Record

A decade of prudential supervision, and the record it produced.

Learn More