Security

Built for money movement, not just messaging

Payments infrastructure earns trust through boring, verifiable controls. These are ours.

Credentials encrypted at rest

Shopify access tokens, WhatsApp API tokens and PhonePe salt keys are encrypted with AES-256-GCM before they touch the database. The dashboard only ever shows a masked value.

Signature-verified callbacks

Every PhonePe callback is validated against the X-VERIFY SHA-256 hash using a timing-safe comparison. An order is never marked paid on an unverified payload.

Per-merchant isolation

Row-level security policies scope every order, credential and log to the merchant that owns it. One merchant can never read another merchant's data.

No card data, ever

ZeroPay handles UPI links only. Card numbers, CVVs and bank credentials are never collected, transmitted or stored by our platform.

Payment data storage in India

In line with the RBI directive on Storage of Payment System Data, payment transaction data is stored on infrastructure located in India by our payment partners.

Auditable webhook trail

Inbound WhatsApp and PhonePe events are logged with their payload and processing state so every state change on an order can be reconstructed.

Reporting a vulnerability

If you believe you have found a security issue, write to our security contact with steps to reproduce. We acknowledge reports within three working days and ask that you do not publicly disclose the issue until a fix is released.