Built for money movement, not just messaging
Payments infrastructure earns trust through boring, verifiable controls. These are ours.
Credentials encrypted at rest
Shopify access tokens, WhatsApp API tokens and PhonePe salt keys are encrypted with AES-256-GCM before they touch the database. The dashboard only ever shows a masked value.
Signature-verified callbacks
Every PhonePe callback is validated against the X-VERIFY SHA-256 hash using a timing-safe comparison. An order is never marked paid on an unverified payload.
Per-merchant isolation
Row-level security policies scope every order, credential and log to the merchant that owns it. One merchant can never read another merchant's data.
No card data, ever
ZeroPay handles UPI links only. Card numbers, CVVs and bank credentials are never collected, transmitted or stored by our platform.
Payment data storage in India
In line with the RBI directive on Storage of Payment System Data, payment transaction data is stored on infrastructure located in India by our payment partners.
Auditable webhook trail
Inbound WhatsApp and PhonePe events are logged with their payload and processing state so every state change on an order can be reconstructed.
Reporting a vulnerability
If you believe you have found a security issue, write to our security contact with steps to reproduce. We acknowledge reports within three working days and ask that you do not publicly disclose the issue until a fix is released.

