Production Access Checklist

How do I qualify for production access after building my sandbox integration?

This checklist covers what to complete before Cybrid grants you production access, after you have
built and tested your integration in sandbox using
one of Cybrid's integration guides, such as the
US B2B payment guide.

Cybrid assesses readiness across three areas — business, compliance, and technical — then
confirms your buildout in a Flow of Funds Review before granting production access.

At a high level, you will:

  1. Confirm your business and compliance readiness.
  2. Complete the technical readiness checklist in sandbox.
  3. Submit a video walkthrough of your buildout for review.
  4. Complete the Flow of Funds Review with Cybrid.
  5. Move to production testing under initial limits, then go live.
ℹ️

This checklist is not exhaustive

Depending on your use case, Cybrid's implementation and compliance teams may identify
additional requirements beyond this list.


Table of Contents

  1. Business readiness
  2. Compliance readiness
  3. Technical readiness
  4. Confirm your sandbox integration end-to-end
  5. Sandbox vs. production
  6. Submit your walkthrough
  7. Flow of funds review
  8. Additional resources

1. Business readiness

  • Your corridor origination (funding) at launch is in the United States or Canada.
  • Your destination corridors (recipients) are supported.
  • You have chosen your primary use case — individual remittance or B2B transfers.
  • You have the developer resources to build and maintain a production environment.
  • Your organization has a compliance point of contact who interfaces with Cybrid's compliance team.
  • You have budgeted for platform and volume costs.
ℹ️

Platform and volume costs

Indicative minimum: approximately $2,500 USD per month in combined platform and volume costs.
Confirm current pricing with Cybrid's Partnerships team during your production discussion.


2. Compliance readiness

  • You have an incorporated entity in Canada or the United States.
  • You have a corporate bank account in your country of incorporation.
  • You have documented your flow of funds (how funds move from sender to recipient) for Cybrid to review.
  • You agree to follow Cybrid's production and go-live testing process.

3. Technical readiness

Complete each step in sandbox. Each links to the guide or recipe with full request and response
detail — this checklist does not repeat the API examples.

3a. Create and verify customers

Create individual customers and/or business customers, then verify identity through the Persona
SDK. Poll or subscribe to webhooks for verification status.

Related: Creating a Customer ·
Verifying a Customer ·
KYB ·
Identity Verification

3b. Create customer accounts

Create a fiat account and a trading account for each verified customer. Accounts have no webhook
event — poll GET /api/accounts/{account_guid} until state transitions to created, then
validate balances.

Related: Creating Platform Accounts ·
Customer Deposit Bank Accounts

3c. Link external bank accounts

If your flow of funds uses Plaid, connect customer bank accounts to enable deposits and
withdrawals.

ℹ️

Optional for some flows

Plaid is not required for Canada-only flows funded by Interac e-Transfer or EFT push, or for
B2B flows that use push funding. Confirm whether it applies to your flow of funds.

Related: Plaid Integration ·
Plaid Funding

3d. Test deposits, trades, and transfers

Simulate deposits and withdrawals, test crypto trades and conversions, and confirm you observe
the expected state transitions through webhooks or the dashboard.

Related: Execute Trades ·
Book Transfers ·
Withdraw Crypto

3e. Set up counterparties

Create a counterparty for each external recipient, associate it with the sending customer, run
verification, and confirm it reaches the verified state.

❗️

Counterparties are mandatory for Travel Rule compliance

Counterparties are not required for basic funding, but they are mandatory before a customer can
send or receive crypto, to satisfy Travel Rule requirements. Partners often reach go-live
without counterparties configured — confirm this step early if crypto transfers are part of
your flow of funds.

Related: Creating a Counterparty ·
Verifying a Counterparty

3f. Complete a remittance plan

Complete the remittance plan template Cybrid provides during implementation for your use case —
your payout corridor and symbols are already enabled as part of your approved setup.

Related: Sending Cross-Border Payments ·
Supported Corridors


4. Confirm your sandbox integration end-to-end

Before requesting the Flow of Funds Review, confirm all of the following are in place:

  • Customer creation (individuals and/or businesses, as defined in your flow of funds)
  • KYC/KYB flows (Persona integration)
  • External bank linking (Plaid), if applicable
  • Trades and transfers
  • Remittance plans and executions
  • Webhooks and event handling working correctly
  • Cybrid User Agreement acknowledged at sign-up and available in settings
  • MFA on customer account creation
  • MFA on every transaction (or MFA at login with a 30-minute session timeout)
  • Persona SDK and Plaid Link SDK integrations, if applicable
  • Customer-scoped access tokens for customer-based API requests
  • API credentials stored securely server-side
  • Counterparties configured, if crypto transfers are part of your flow of funds

5. Sandbox vs. production

Production behaves differently from sandbox in several ways. Review these before planning your
production testing timeline.

AreaSandboxProduction
KYC/KYBSimulated with fake identity data; approved in about a minuteReal Persona verification with real identity data; verification links expire after 1 hour
PlaidSimulated with fake bank data (test credentials)Real Plaid Link connections with real bank account data
Funding transfersAutomatically fronted to avoid non-sufficient funds (NSF) errorsReal balances apply — transfers can fail due to non-sufficient funds (NSF)
TimingDeposits, trades, and transfers settle almost instantlyAsynchronous and event-driven — may take hours or days
Bank configurationSelf-configured, unrestrictedCybrid-provisioned with approved currencies, assets, and rails only
Error handlingLimited error scenariosRequires retry logic, idempotency, and backoff handling

Related: How Does the Sandbox Environment Differ


6. Submit your walkthrough

Once every item above is complete, record a video walkthrough (for example, a Loom or Zoom screen
recording) of your technical integration and send it to [email protected].

Cybrid reviews the walkthrough. If your application is ready, Cybrid's Partnerships team reaches
out to schedule a meeting to discuss your flow of funds and partnership agreement, and to begin
the Flow of Funds Review.


7. Flow of funds review

The Flow of Funds Review is the gate between sandbox and production. Cybrid validates that your
implementation matches your compliance-approved flow of funds and that required security controls
are in place. Expect this review to take 2-3 days.

7a. Complete the flow of funds demo

Walk through how funds move in your production setup, to confirm compliance and operational
readiness.

7b. Cross-check your app against the approved flow of funds

Cybrid validates that:

  • All movement types (deposits, withdrawals, trades, transfers) appear only as defined in your
    approved flow of funds.
  • Supported assets, currencies, and corridors match the approved version.
  • Customer types (individual or business) match — no new customer classes have been added.
  • Integration points (Plaid, Persona, crypto rails) are consistent with the approved version.
  • No additional accounts or counterparties exist beyond scope.
❗️

No unauthorized flows

If your app includes money movement types, corridors, customer types, or integrations that were
not in your approved flow of funds, you must go through Cybrid's Flow of Funds Change Control
process before proceeding.

7c. Verify compliance and security

Cybrid confirms:

  • Multi-factor authentication (MFA) is enforced on login and on every transaction.
  • The Cybrid User Agreement and
    Privacy Policy are accessible in your application, both at sign-up and in a reference section.
  • API keys and credentials are managed securely.

Related: Security Considerations

7d. Align on remaining steps to production

Cybrid and your team:

  • Confirm any remaining partner compliance approval and agreement steps are complete.
  • Review and summarize remaining action items and confirm all dependencies are complete.
  • Clarify responsibilities for production organization and bank creation, and the production test
    plan.
  • Confirm the communication cadence for the production phase.
  • Document go/no-go criteria and an expected production testing start date.
ℹ️

Production testing limits

Once approved, Cybrid provisions a production bank with a $100 USD daily transaction limit. Test
your complete on-ramp and payouts flow within this limit. After Cybrid reviews your full
end-to-end test results, the limit is lifted and you can begin live operations.

Checkpoint

Your flow of funds is approved, compliance and security checks pass, and you have a confirmed
go-live date. You're ready to move to production testing.


8. Additional resources



Did this page help you?