Enterprise-grade security

Built for Security

PhonixPay is not currently PCI-DSS, ISO 27001, or SOC 2 certified. Here is exactly what our architecture does to protect your payments and data.

Card Data Isolation

Card payments are handled directly inside our payment partners' own secure, hosted checkout. PhonixPay never receives or stores your customers' card numbers, expiry, or CVV.

Encryption in Transit

All traffic to and from PhonixPay is served over TLS/HTTPS.

Verified Webhooks

Every payment confirmation is cryptographically signature-verified and independently re-checked with the payment provider before a transaction is marked complete.

Account Protection

Two-factor authentication is available for merchant and admin accounts, and every public API endpoint is rate-limited.

Network Protection

PhonixPay sits behind Cloudflare — DDoS mitigation, a managed web application firewall, and bot mitigation filter traffic before it ever reaches our servers. Our TLS configuration holds an A+ rating from Qualys SSL Labs.

Engineering practices

Idempotent payment processing
Server-side re-verification of every payment
Database-level locking on financial transactions
Regular internal security reviews