Trust
What we hold,
and what we refuse to.
Most of this page is about data we deliberately never touch. That is the design: the smaller the blast radius, the shorter your diligence.
Data boundary
Where every field actually lives
If a row says never, it means the system has no code path that could store it — not that we have a policy against it.

No fund flow
Money moves around us, never through us
There is no TapProof account anywhere in the settlement path. It is not a policy — there is no code path that could open one.
Attestation
A device earns the right to transact, every time
Acceptance on a phone somebody owns is only safe if the phone can prove what it is. PCI MPoC requires a back-end attestation and monitoring component; it is ours, and it is the part an assessor spends the most time on.

Play Integrity

Hardware identity

Continuous monitoring

Fail closed
Proof of presence
Who took this money, and where were they standing?
This is the question every operator away from a counter eventually has to answer — to a customer, an auditor, a card scheme or a regulator.
TapProof binds the operator’s verified identity, the attested device, the location and the timestamp to the transaction itself. Not as a report generated afterwards, but as the record that was created at the moment it happened.
Every event carries a per-account sequence number and an HMAC-SHA256 signature over a timestamped body. A gap is visible. A tampered payload fails. A captured payload cannot be replayed later.
- ▍
Two refusals recorded. Both are evidence.

Hardware-backed keystore identity
Identity
A device that cannot lie about what it is
Enrolment generates a key inside the handset's secure hardware, StrongBox where the model has it. The device's identity is the hash of that key.
It cannot be spoofed by copying a preferences file, cannot be moved to another handset, and dies with a factory reset — which is exactly the behaviour an acquirer expects from an acceptance device.
Sector regimes
The rules our customers have to satisfy
TapProof is not a compliance product. It produces the evidence that compliance regimes ask for, and in one case enforces the rules directly.
Time
Some sectors regulate when you may knock
Where they do, the window is enforced at the moment of contact rather than audited afterwards — and the refusal is written to the record with a reason code.
A platform that merely logs an out-of-hours visit has produced evidence against its customer. One that refuses it has produced evidence for them. That distinction is the entire point of building the rule into the software.

A permitted window, enforced not reported
Posture
Certification, stated honestly
We will not claim a certification we do not hold. Your risk team will check, and one overclaim ends the conversation.

Signed
A record that can be checked, not just read
HMAC-SHA256 over a timestamped body, sequenced per account. Tampering fails verification; a captured payload cannot be replayed at you later.
The boundary
Why we are not a payment aggregator
Under the RBI Payment Aggregator Directions, 2025, aggregating transactions where the acceptance device and payment instrument are physically proximate requires PA-P authorisation. We do not do that.
