Security

How we protect your data

PhonixPay is not currently PCI-DSS, ISO 27001, or SOC 2 certified. Here is what our architecture actually does to keep your payments and data safe.

A-
92 / 100

Internal security score

Our own self-assessed score, not a third-party certification. From a security review covering permission checks, credential handling, dependency vulnerabilities, and webhook signature verification — each fix re-verified against live production, not just the code. Last reviewed August 2026.

A+
SSL Labs rating

Independently verifiable

Our TLS/HTTPS configuration, graded by Qualys SSL Labs — a free, independent scanner anyone can run. Click through to see the live result for phonixpay.com yourself.

ssllabs.com/ssltest →
Card data never touches our servers

Card payments are handled directly by our payment partners inside their own secure, hosted checkout — card numbers, expiry, and CVV are never received or stored by PhonixPay.

Encryption in transit

All traffic to and from PhonixPay is served over TLS/HTTPS.

Verified webhooks

Every payment confirmation is cryptographically signature-verified and independently re-checked against the payment provider before a transaction is marked complete — we never trust a callback at face value.

Two-factor authentication

Available for merchant and admin accounts to protect account access.

Rate limiting

All public-facing endpoints are rate-limited to reduce abuse and automated attack attempts.

Engineering practices

Idempotent payment processing (no duplicate charges from retried callbacks)
Regular internal security reviews
Database-level locking on financial transactions to prevent race conditions
Server-side re-verification of every payment before crediting an account

Questions about our security?

Reach out and we'll answer directly.

compliance@phonixpay.com