Skip to content

Security

Platform security

Verified security principles for website and platform operations. Certifications and provider attestations are listed only when AQPAY is entitled to present them.

Security principles

  • Encrypted transport for public website and platform traffic
  • Controlled access to technical and administrative systems
  • Clear separation of sandbox and production environments
  • Authentication and credential controls for authorised users
  • Monitoring and logging without unnecessary retention of sensitive data
  • Secure credential handling and rotation expectations
  • Vulnerability management and incident response processes
  • Data minimisation in documentation, support and website analytics

What this page does not claim

Unless independently verified and authorised for public statement, AQPAY does not claim PCI DSS certification, ISO 27001, SOC 2, penetration-test cadence, 24/7 SOC coverage, zero-trust architecture, end-to-end encryption ownership, or card-data tokenisation ownership on this site.

Where an underlying gateway provider holds certifications, those attestations belong to the provider and must not be presented as AQPAY certifications without legal entitlement.

Merchant and partner responsibilities

  • Protect credentials and apply least-privilege access
  • Keep secrets out of client-side code and public repositories
  • Use approved domains, callbacks and IP controls where required
  • Validate webhook authenticity and handle duplicates safely
  • Report suspected compromise promptly through authorised channels

Report a vulnerability

See the responsible disclosure policy for scope, expectations and reporting guidance.