Security Policy
The security of our payment gateway integrations and partner APIs is paramount. At sathsafar, we utilize layered network controls, multi-factor face validation systems, and strict IP whitelisting to protect all systems.
1. Face Validation Login & IP Shield
To prevent credential stuffing and unauthorized account takeovers, our portal uses real-time mobile face validation verification. Face Validation security scans only the user's face to verify if the user is real or not. This is not a biometric scan.
- Auto-Detection: If a login is attempted from an unrecognized IP address or different browser client, the system intercepts the flow and demands a mobile face scan.
- Hard Lock Firewall: If a face validation face verification fails, the requesting client IP address is immediately banned in our database, blocking all website access for that system.
2. REST API Key Security
API endpoints are protected by individual secret keys (`x-api-key`). Security measures include:
- API Keys are hashed in transit and monitored by latency meters.
- Server whitelisting: Partners must define hosting IP addresses under secure OTP verification before hits are processed.
3. Data Encryption Standards
All network communication between merchant servers and our API Hub Platform utilizes secure HTTPS connections with TLS 1.3 protocol. Database storage is protected behind multi-tier virtual private clouds (VPC).
4. Audit Logs & Active Sessions
The platform logs every credential change, IP add request, and login attempt. Inside your Partner Profile panel, you can view your active device sessions with browser type, IP, and location, and terminate any session instantly.
5. Vulnerability Disclosure
We encourage researchers to report vulnerabilities. If you discover a security flaw, please contact our security team at sathsafar24@gmail.com instead of public disclosure.