VoltPay

Payment Orchestration Security & Compliance

Security controls for unified payments API traffic, payment routing engine operations, and merchant data protection across providers.

Security Infrastructure

Encryption

Traffic to our API, dashboard and hosted checkout is encrypted in transit with TLS.

Infrastructure

Public traffic is served through a CDN edge, internal services communicate over private networks, and production databases are backed up regularly.

Access Control

Role-based access controls (RBAC) and organization-scoped API keys with optional IP allowlisting.

Monitoring

Automated monitoring of service health, payments and payouts, with alerts routed to our operations team.

PCI DSS Practices

Payment Card Industry Standards

Card data is handled per PCI DSS (Payment Card Industry Data Security Standard) requirements, with encrypted transport and restricted access to payment data.

  • Encrypted transport for card payment flows
  • Access to payment data restricted by role
  • 3-D Secure authentication on card payments where supported

Data Protection & Privacy

Personal Data (GDPR)

We process personal data of EU residents in line with the General Data Protection Regulation (GDPR). You can contact us to:

  • • Access, correct, or delete your personal data
  • • Receive a copy of your personal data

Data Retention

We retain data only as long as necessary for business operations and regulatory compliance:

  • • Transaction data: 10 years (regulatory requirement)
  • • Account information: Active account + 7 years
  • • Audit logs: 2 years minimum
  • • Marketing data: Until consent withdrawn or account closed

Data Processing

Personal data is processed securely with:

  • • Encryption in transit
  • • Access limited to authorized personnel only
  • • Regular backups of production databases

Fraud Prevention & Risk Management

Transaction Monitoring

Real-time monitoring of transactions for suspicious patterns, velocity checks, and anomaly detection to prevent fraud before it occurs.

3D Secure Support

Support for 3D Secure (3DS) authentication including 3DS2 for enhanced security and liability shift on card transactions.

Risk Scoring

Automatic risk assessment based on transaction patterns, customer behavior, and historical data to flag high-risk transactions.

API Security

API Authentication

  • Authorization header contract: Authorization: Bearer <API_KEY>
  • Webhook signature verification using HMAC-SHA256
  • IP whitelisting available for enhanced security
  • Rate limiting to prevent abuse

Webhook Security

All webhook deliveries include security headers:

  • • X-Webhook-Signature - canonical header in the format sha256=<hex>
  • • X-Webhook-Timestamp - Timestamp to prevent replay attacks
  • • X-Webhook-Id - Unique ID for deduplication

Incident Response

Security Incident Protocol

In the event of a security incident, we follow a structured response process:

  1. Immediate containment and assessment
  2. Notification to affected merchants without undue delay, and to regulators where required by law
  3. Transparent communication about impact and remediation
  4. Post-incident analysis and security improvements

To report a security vulnerability, please email [email protected] with details.

Questions About Security?

If you have specific security questions or need additional information for your compliance review, please reach out to our team.

Security Inquiries: [email protected]

We're happy to provide additional documentation, answer questions about our security practices, or discuss your specific compliance requirements.