Security

Security built into the financial core

Every balance shown in your dashboard is a view into an append-only ledger, not a number a client request can change. These are the controls that protect it.

Authentication

  • Enforced password strength
  • Email verification
  • Optional/required 2FA based on risk policy (coming soon)
  • Session revocation and secure password reset

API Keys

  • Stored as hashes, never in plaintext
  • Secret shown once, at creation only
  • Revocation and rotation supported
  • Last-used timestamp recorded per key

Webhooks

  • HMAC signature verification on every delivery
  • Replay protection and event-ID deduplication
  • Delivered over HTTPS only
  • Automatic retries with dead-letter handling on repeated failure

Financial Operations

  • All balance and commission math computed server-side, never in the browser
  • Idempotency keys on retryable financial operations
  • Withdrawal risk checks, destination validation, and rate limiting
  • Immutable audit log across account and payment actions

Data isolation

Row Level Security is enabled on every merchant-scoped table. A merchant's session can only read or write records tied to accounts it belongs to — ledger, transaction, and order records are written only by trusted backend logic, never directly by a merchant request.

Have a security question or want to report an issue?

Reach out and our team will follow up directly.

Contact Us