Security

PCI Compliance

Security guidance for the hosted checkout, API usage, merchant access, and payment data handling workflows.

Core Practices

Use HTTPS

Production checkout and merchant access should always run over HTTPS.

Protect API Keys

API keys belong on merchant servers only and should not be exposed in browser JavaScript.

Restrict Sensitive Files

Configuration, library, and storage paths are blocked from direct browser access.

Payment Handling

Hosted checkout keeps payment collection in a controlled flow. Admin review tools should be used only by authorized administrators.

Merchant Responsibilities

Merchants should use strong passwords, rotate keys when needed, restrict access to their systems, and review integration behavior before production use.

Related Pages