Enterprise-grade protection at every layer
End-to-End Encryption
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). API keys are hashed with bcrypt. Database fields containing sensitive data use column-level encryption.
API Key Security
HMAC-SHA256 signed webhook payloads. Separate test/live key environments. Key rotation without downtime. Rate limiting per IP and per API key.
Smart Contract Audits
All payment smart contracts undergo third-party security audits before deployment. Fee parameters are immutable once deployed — no one, including us, can modify them.
Infrastructure Isolation
Production systems run on isolated infrastructure with private networking. Database access requires multi-factor authentication. No direct SSH access to production.
Monitoring & Alerting
24/7 automated monitoring of all systems. Real-time alerts for anomalous activity. Comprehensive audit logs for every API call, login, and configuration change.
Data Protection
Minimal data collection by design. We don't store customer PII. Payment data is encrypted and access-controlled. Full data deletion available on request.
Authentication
Two-factor authentication (2FA) for all accounts. Session management with automatic expiry. IP allowlisting for API access. OAuth 2.0 for partner integrations.
Network Security
DDoS protection via Cloudflare. Web Application Firewall (WAF) rules. CORS policies. Content Security Policy headers. Rate limiting at edge.
Non-Custodial Architecture
For crypto payments, funds flow directly from customer to merchant via smart contract. We never hold, custody, or have access to user funds. Zero counterparty risk.
Regulatory compliance is built in
We partner with licensed, regulated infrastructure providers to ensure full compliance across every jurisdiction.
KYC / AML
Identity verification and anti-money laundering checks through regulated partners. Ongoing transaction monitoring for suspicious activity.
Licensed Infrastructure
Fiat payments powered by Airwallex (85+ global licenses). Crypto payments via smart contracts with transparent, auditable fee logic.
Data Privacy
GDPR-ready data handling. Minimal data collection. Right to deletion. Encrypted storage. No sale of personal data to third parties.
Fraud Prevention
Real-time fraud scoring for fiat transactions. Address screening for sanctioned wallets. Velocity checks and anomaly detection.
Report a Vulnerability
Found a security issue? We take every report seriously. Please email our security team directly. We respond within 24 hours.
security@zateway.com