Skip to main content

    Trust · Security & Privacy

    How transaction records, access, and notifications are protected.

    Security is described by the controls we actually run, not by badges. This page lists what is enabled today for ArosaPay accounts and merchant APIs.

    Access

    Authenticated sessions

    Merchant and admin sessions are backed by ArosaPay authentication with per-origin storage and session timeouts.

    MFA available

    Multi-factor authentication is available for merchant accounts and required for admin accounts on sensitive actions.

    Role-based access

    Admin capabilities are governed by role-based permissions with sensitive-action gating.

    Compromised-password checks

    Sign-up and password changes screen against known compromised credentials.

    Records

    Row-level access

    Buyer, merchant, and admin data access is enforced at the database row level with policies scoped to identity.

    Audit trail

    Sensitive admin actions are recorded with actor, action, and target for later review.

    Webhook security

    Signed events

    Every outbound webhook carries X-ArosaPay-Signature and X-ArosaPay-Timestamp for verification and replay protection.

    Idempotent delivery

    Events carry X-ArosaPay-Event-Id so merchants can deduplicate retries safely.

    Data handling

    Personal data

    Personal data is collected for account creation, KYC, and dispute handling. Handling is described in the privacy policy.

    PII access

    Access to personal data by internal reviewers is dual-controlled and logged for forensic review.

    What we do not claim

    No badges we haven't earned.

    This page lists controls that are actually enabled. It does not assert regulatory certifications or partnerships that have not been publicly confirmed.

    Read the privacy policy