Security
Security-focused payment infrastructure
These are the controls implemented in the mPay platform today. We describe what exists rather than claiming a certification or standard.
Encrypted connections
The application and API are served over HTTPS.
Two-factor authentication
Accounts can enable TOTP two-factor authentication with single-use recovery codes, and sensitive actions can require a current code.
API request authentication
Server-to-server calls require a secret API key. Keys are issued, listed and revoked from the dashboard.
Signed webhooks
Every webhook delivery is HMAC-SHA256 signed over the timestamp and body, retried with backoff, and can be redelivered.
Audit logging
Account and administrative actions are recorded to an audit trail.
Role-based access
Administrative surfaces are gated on the account type resolved server-side, and are re-checked on every request.
Payment-status monitoring
A reconciliation process compares payments against provider state so a collected payment that has not settled is visible rather than silent.
Session security and app lock
Sessions are token-based, and the merchant app requires a PIN on launch which also authorises payouts.
Reporting a vulnerability
Report suspected vulnerabilities to Official domain-based support contact details will be published before production launch.. Please include steps to reproduce. Do not include customer data, credentials or private keys in your report.
mPay makes no claim on this page to hold any security certification, compliance attestation, industry accreditation or financial-services licence. Where a specific compliance question affects your integration, contact mPay and it will be answered directly with whatever documentation exists.
Ready to simplify how you receive payments?
Create your mPay account or contact our team to discuss payment links, hosted checkout and website integration.
Service availability, supported payment methods, settlement timing and fees may vary.