How I Built a Money-Safe Escrow Payment System
TrustBrig — Multi-Currency Escrow Marketplace (USA)staging.trustbrig.com
TrustBrig is a multi-currency escrow marketplace for a US client — a platform where strangers can transact safely across currencies and borders. A buyer's funds are held in escrow and released to the seller only when deal conditions are met. The hard part isn't the UI; it's moving real money without ever losing or double-paying a cent, on top of a Banking-as-a-Service rail (Buckzy) that only exposes a single pooled balance.
The Challenge
- 1Real money across 6+ currencies with escrow holds — a single lost or doubled transaction is catastrophic and hard to unwind
- 2The payment provider shows one pooled balance and has no return webhooks (email only) — the platform must own the source of truth and all safety logic
- 3Provider webhooks are unsigned and can arrive twice or out of order — they cannot be trusted blindly
- 4Funds must not be withdrawable before settlement is final (ACH/wire return windows), or the platform eats the loss
- 5Users must not be verified twice (KYC), and dispute outcomes must move money correctly (refund / partial / release / split)
The Approach
Double-Entry Ledger as Source of Truth
Built an internal double-entry ledger (integer minor units, balanced-at-commit) as the authority for who owns what — never the provider's pooled balance. Every movement is two balanced entries, append-only and auditable.
Transactional Outbox
No payment API is ever called inside a user request. State changes write a ledger journal and an instruction row in the same DB transaction; a worker dispatches it after commit — so a crash can never lose or duplicate a money move.
Idempotent, Verified Webhooks
Every external call carries an idempotency key; every inbound webhook is deduplicated and confirmed-by-GET before acting (the provider's payloads are unsigned). Retries can never double-charge or double-pay.
Escrow Engine + Settlement Gating
Standard and milestone escrows with hold/release/refund, inspection windows, auto-release timers, and mutual cancellation. Withdrawals are gated behind settlement finality so money only leaves once it's irreversible.
KYC Reliance, Disputes & Step-Up Auth
Integrated KYC (Didit) with a reliance model so users verify once; built dispute resolution & mediation with money-correct outcomes; and added step-up re-authentication (2FA/passkeys) for every fund-moving action.
The Results
0
Double-payments (by design)
2-way
Ledger vs provider reconciliation
80+
Payout countries (rail)
6+
Currencies + stablecoins
- Integrated the Buckzy BaaS rail end-to-end — wallets, funding, FX, account-to-account transfers, and global payouts — verified live in sandbox
- KYC reliance model (Didit) so users complete verification only once
- Dispute resolution & mediation with refund / partial / release / split outcomes
- Step-up re-authentication (2FA / passkeys) and RBAC on all money actions
Key Takeaway
“Moving real money is a discipline, not a feature. The ledger — not the provider's balance — is the source of truth. Idempotency, a transactional outbox, and reconciliation turn an unforgiving problem into a reliable, auditable system.”


