Trust built into every transaction
Identity, eligibility, approvals, transaction controls and audit history sit inside the flow, not beside it.
Three layers of control
Every control below is documented platform behaviour, and each layer links to the page where it runs.
Identity and eligibility
- KYC, KYB and sanctions screening inside the platform
- Eligibility read per customer and per country
- Product activation once the requirements are met
Transaction controls
- Two-person release on FX orders, where it is configured
- Idempotent execution: a retry returns the original payment
- Card details returned encrypted to a key you hold
Operational integrity
- Signed events, with event_id as the dedupe key
- Transaction history against the same customer record
- An application carries its own history of what changed
Evidence behind the controls
What a reviewer can check, rather than what a badge would assert.
- 99.99%
API uptime, rolling.
- Two-person release
Available on FX orders, for the thresholds your team configures.
- Audit history
Transaction and change records remain traceable, with the actor named on each one.
- Signed and idempotent flows
Events arrive signed with a dedupe key, and a retried payment returns the original.
What your diligence team can request
Three routes, named for the review being run. A single contact address makes a security reviewer and a developer guess which one they are.
Security documentation
For security reviews, architecture and relevant control documentation.
Compliance and diligence
For entity structure, regulatory questions and programme review.
Technical review
For API behaviour, controls and implementation details.
Need to review Gravv before you build?
Request the documentation your security, compliance or technical team needs.