Built for Security
PhonixPay is not currently PCI-DSS, ISO 27001, or SOC 2 certified. Here is exactly what our architecture does to protect your payments and data.
Card Data Isolation
Card payments are handled directly inside our payment partners' own secure, hosted checkout. PhonixPay never receives or stores your customers' card numbers, expiry, or CVV.
Encryption in Transit
All traffic to and from PhonixPay is served over TLS/HTTPS.
Verified Webhooks
Every payment confirmation is cryptographically signature-verified and independently re-checked with the payment provider before a transaction is marked complete.
Account Protection
Two-factor authentication is available for merchant and admin accounts, and every public API endpoint is rate-limited.
Network Protection
PhonixPay sits behind Cloudflare — DDoS mitigation, a managed web application firewall, and bot mitigation filter traffic before it ever reaches our servers. Our TLS configuration holds an A+ rating from Qualys SSL Labs.