Production Readiness for Cybrid
This page maps each Cybrid production requirement to where it's implemented. Use it to guide your implementation review call.
Environment: UNKNOWN
Sandbox mode — switch CYBRID_ENV to "production" after Cybrid approves your review.
Cybrid Requirements Checklist
End-to-end demo of flow of funds
Deposit → internal ledger → bank transfer / cross-border USDC / crypto withdrawal — all functional
Cybrid security & legal requirements
All 5 sub-requirements implemented (see below)
Book implementation review meeting
Schedule your demo at meetings.hubspot.com/colin-branch/implementation-review
Cybrid User Acknowledgment
ImplementedUsers must accept the Cybrid User Agreement during and after onboarding.
How it's implemented
When a user completes KYC and gets a Cybrid customer GUID, the Dashboard automatically shows a modal with the full Cybrid User Agreement. The user must check "I have read and agree" before accessing their account. Acceptance is stored with a timestamp.
Demo steps
- 1
Log in as any verified user (e.g. the test account)
- 2
If not yet accepted, the Cybrid Agreement modal appears on the Dashboard
- 3
Acceptance is recorded on the UserProfile entity: cybrid_agreement_accepted = true, cybrid_agreement_accepted_date = timestamp
MFA on User Creation
ImplementedMulti-factor authentication enforced when a new user account is created.
How it's implemented
Registration requires email + password (Factor 1). After registering, a 6-digit OTP code is sent to the user's email (Factor 2). The account is not activated until the OTP is verified. Additionally, all users must complete KYC document verification before account activation.
Demo steps
- 1
Go to the registration page
- 2
Register with a new email + password
- 3
OTP verification screen appears — enter the code sent to email
- 4
After OTP, user is redirected to Onboarding for KYC document upload
MFA on Transfer Creation
ImplementedEvery money movement requires a transaction PIN as a second factor.
How it's implemented
Before any transfer (bank transfer, cross-border, internal, USDC conversion, or crypto withdrawal), the user must enter their 4-digit Transaction PIN. If no PIN is set, they are prompted to create one first. The PIN is hashed before storage. This applies to: processTransfer, cybridConvert, and cybridWithdraw.
Demo steps
- 1
Go to Send Money page as a verified user
- 2
Fill in transfer details and click Continue
- 3
Transaction PIN modal appears — user must enter PIN to authorize
- 4
Same flow on Convert to USDC and Withdraw Crypto pages
Customer-Scoped Access Tokens
ImplementedAll customer operations use short-lived, customer-scoped tokens via POST /api/customer_tokens.
How it's implemented
The backend functions cybridConvert and cybridWithdraw call Cybrid's POST /api/customer_tokens endpoint to generate a token scoped to the individual customer with only the permissions needed (quotes:execute trades:execute or quotes:execute transfers:execute). These tokens are never exposed to the frontend — all Cybrid API calls happen server-side in backend functions.
Demo steps
- 1
This is enforced in the backend — no UI to show
- 2
Show Colin the code in base44/functions/cybridWithdraw/entry.ts (getCustomerToken function)
- 3
Also in base44/functions/cybridConvert/entry.ts
- 4
Tokens are created per-request and are never stored or cached
Safely Store API Credentials
ImplementedAll Cybrid API credentials are stored as server-side secrets — never in client code.
How it's implemented
CYBRID_CLIENT_ID, CYBRID_CLIENT_SECRET, and CYBRID_BANK_GUID are stored as Base44 app secrets (encrypted at rest). They are only accessed via Deno.env.get() inside backend functions. The frontend never imports or references these credentials. IP allowlists can be configured on the Production page to restrict API access to your server egress IPs.
Demo steps
- 1
Show the Production page — IP allowlist configuration
- 2
Credentials are in Settings → Environment Variables (not in source code)
- 3
All Cybrid calls go through base44/functions/ (Deno backend)
Ready for your implementation review
All 5 Cybrid security and legal requirements are implemented. Book your demo at meetings.hubspot.com/colin-branch/implementation-review. After approval, switch CYBRID_ENV from "sandbox" to "production" in your app secrets.