Under developmentBitcoin Quay is an early commercial product, not a production service, and not for member data. It is built on the open-source Bitcoin Commons but is a separate commercial project and does not speak for it.

Security and compliance

Scope discipline over stickers

There is no such thing as “compliant” Bitcoin node software. Compliance is something your institution demonstrates through its architecture, its process, and its evidence. What a vendor can honestly offer is a product that makes that easier and a straight account of how it works. That is what this page is.

An audit trail examiners can follow

Sensitive actions are logged so an examiner can trace what happened, who approved it, and when. We do not claim SOC, PCI, or NACHA certification anywhere on this site.

You keep your own vendors

Bitcoin Quay connects only to a reviewed list of systems. Your core, your OFAC and AML screening, and your ACH all run through your own vendors and processors. Bitcoin Quay does not become your ACH originator or your BSA system of record.

Member data stays out

Bitcoin Quay is built to look up what it needs without storing member personal information. It handles no card numbers, which keeps it outside PCI card-data scope. The forms on this site never collect member data.

Dual-control by design

No single person can move money or take a sensitive action alone. Money movement is a request tied to your payment vendor's decision, not a free-form send.

This page is a plain description for early conversations. It is not a security whitepaper, an attestation, or a substitute for your own third-party risk review (TPRM).

Request a briefing