Security

How SPV keeps your data and payments safe

Every merchant account, API key, and payment SMS is protected end-to-end — built for handling real money from day one.

Domain-Locked API Keys

Your API key binds permanently to your website domain the first time it's used. Even if a key leaks, it cannot be called from another server or domain.

Encrypted Data at Rest & In Transit

All merchant data lives in Google Firebase Firestore. KYC documents are stored as encrypted fields, and every connection between the app and Firebase runs over TLS/HTTPS.

Firestore Security Rules

Strict per-account access rules mean you can only ever read your own transactions and profile data. Admin access is limited to verification and support.

Fraud-Proof Transaction Matching

SPV cross-checks Transaction ID, exact amount, provider, and time window against the live SMS — a screenshot or fake TxnID can never pass verification.

Mandatory KYC Verification

Every merchant completes identity verification with NID/Passport/TIN and a live selfie before going live, reviewed by our admin team within 24 hours.

Minimal SMS Scope

SPV only reads payment confirmation SMS from bKash, Nagad, and Rocket. Personal messages, OTPs, and every other SMS on your phone are never accessed or stored.