Transport
Use HTTPS for merchant pages, backend requests, return URLs, and callbacks.
Security approach
A secure integration limits credential exposure, verifies payment status, validates events, records references, and makes unusual states visible.
Apply for merchant accessControl layers
Commercial noteThis page describes an intended security approach. It does not claim a certification, licence, audit result, or scheme membership.
Use HTTPS for merchant pages, backend requests, return URLs, and callbacks.
Keep secret values on the server, use separate test and production access, and rotate when required.
Confirm the authoritative payment status before fulfilment, access, or accounting updates.
Validate incoming notifications, handle duplicates safely, and preserve event references.
Restrict merchant access, review unusual activity, and keep refund actions accountable.
Merchant responsibilities
The merchant website, application, staff access, and fulfilment logic remain part of the payment security boundary.
Use current software, secure administration, accurate product information, and visible customer policies.
Do not trust query parameters, browser messages, or customer screenshots as proof of payment.
Give staff the minimum access required and remove accounts that are no longer needed.
Know how to pause fulfilment, preserve evidence, and contact the payment team when a transaction looks wrong.