Skip to content
No hardwareTurn the phones your people already carry into card machines. No terminal to buy or rent.Get started →
TapProofGet started

How it works

Four checks,
then the tap.

Everything that could fail is decided before the customer's card comes out. By the time the reader arms, the only thing left to happen is the payment.

Try it

Press the circle and watch the real sequence

These are the actual stages the platform runs, with the actual timings. Nothing here is a decorative animation.

click the circle to run the real sequence

Trace0000 ms
  1. Session requested0ms
  2. Device attested340ms
  3. Operator authorised640ms
  4. Rail selected900ms
  5. Reader armed1180ms
  6. Card read1900ms
  7. Sent to acquirer2260ms
  8. Approved3000ms

Four checks complete before the reader is even armed. Nothing fails in front of the customer.

Why this order

The customer never sees a failure

A terminal that declines after the card is presented has already cost you the moment — and often the customer's patience. Every check that can refuse runs first.

Check 01

Session requested

An idempotency key is issued before anything else happens. A re-tap, a lost network reply or an impatient second press can never charge the customer twice — the second request resolves to the first result rather than creating a new one.

Check 02

Device attested

The handset proves it is what it claims: a Play Integrity verdict verified server-side, a hardware-backed keystore identity, and checks for root, emulation, an attached debugger and screen overlays. No valid attestation means no session. It fails closed, always.

Check 03

Operator authorised

The person holding the phone is verified against your roster. Where a sector regulates when contact may happen, the permitted hours are enforced here too — and a refusal is written to the record rather than silently swallowed.

Check 04

Rail selected

Amount, merchant configuration and connectivity decide what can carry this payment. Only then is the reader armed. The app renders whatever it is told to render; it holds no policy of its own, which is what stops a stale app from making an out-of-date decision.

Then

What lands in your system

The tap is over in under a second. The record it produces is the part that keeps working for you afterwards.

Every step arrives HMAC-signed and sequenced, including the refusals. Values are absolute rather than deltas, so your ledger cannot drift from ours.

Event stream · your endpointHMAC-SHA256

Two refusals recorded. Both are evidence.

Under a second

Then the part the customer sees

A tap. Everything above happened while they were still reaching for their card.

Before any of that

How you get live in the first place

You sign up with TapProof. A licensed bank or payment aggregator onboards you and holds your contract. Then acceptance runs on our software.

Step 1 of 4 · You

Tell us about the business

Two minutes. Business name, category, where your people work, and how many phones you need to turn into terminals.

No documents at this stage. Nothing is submitted anywhere yet.