Every merchant account, API key, and payment SMS is protected end-to-end — built for handling real money from day one.
Your API key binds permanently to your website domain the first time it's used. Even if a key leaks, it cannot be called from another server or domain.
All merchant data lives in Google Firebase Firestore. KYC documents are stored as encrypted fields, and every connection between the app and Firebase runs over TLS/HTTPS.
Strict per-account access rules mean you can only ever read your own transactions and profile data. Admin access is limited to verification and support.
SPV cross-checks Transaction ID, exact amount, provider, and time window against the live SMS — a screenshot or fake TxnID can never pass verification.
Every merchant completes identity verification with NID/Passport/TIN and a live selfie before going live, reviewed by our admin team within 24 hours.
SPV only reads payment confirmation SMS from bKash, Nagad, and Rocket. Personal messages, OTPs, and every other SMS on your phone are never accessed or stored.