Security principles
- Encrypted transport for public website and platform traffic
- Controlled access to technical and administrative systems
- Clear separation of sandbox and production environments
- Authentication and credential controls for authorised users
- Monitoring and logging without unnecessary retention of sensitive data
- Secure credential handling and rotation expectations
- Vulnerability management and incident response processes
- Data minimisation in documentation, support and website analytics
What this page does not claim
Unless independently verified and authorised for public statement, AQPAY does not claim PCI DSS certification, ISO 27001, SOC 2, penetration-test cadence, 24/7 SOC coverage, zero-trust architecture, end-to-end encryption ownership, or card-data tokenisation ownership on this site.
Where an underlying gateway provider holds certifications, those attestations belong to the provider and must not be presented as AQPAY certifications without legal entitlement.
Merchant and partner responsibilities
- Protect credentials and apply least-privilege access
- Keep secrets out of client-side code and public repositories
- Use approved domains, callbacks and IP controls where required
- Validate webhook authenticity and handle duplicates safely
- Report suspected compromise promptly through authorised channels
Report a vulnerability
See the responsible disclosure policy for scope, expectations and reporting guidance.