Non-custodial by architecture
Payfim only ever sees public receiving addresses. There are no private keys on the server, no hot wallet and no balance to steal. Even a fully compromised web server cannot move your coins.
Prices are set server-side
Store plugins create invoices through an authenticated server-to-server API. The amount never travels through the shopper's browser, so it cannot be edited with developer tools - a common flaw in simpler crypto plugins.
Every payment is matched exactly once
- Each open invoice gets a unique amount (or a unique XRP destination tag / Monero subaddress).
- Transaction hashes are stored with a database uniqueness constraint, so one blockchain payment can never pay two orders.
- Payments must arrive after the quote was created and must reach the confirmation threshold you set.
Signed, re-verified webhooks
Notifications to your store carry an HMAC-SHA256 signature over a timestamp and the exact body, and are rejected after five minutes. Our official plugins additionally re-read the invoice from your gateway and compare the amount and currency with the order before marking it paid.
Hardened dashboards
- Two-factor authentication (TOTP) for the gateway dashboard and the payfim.com client area.
- CSRF tokens on every form, strict Content-Security-Policy, secure HttpOnly SameSite cookies and idle session timeouts.
- Rate limiting and CAPTCHA against brute-force and spam, plus an optional admin IP allow-list.
- Audit logs of sign-ins and sensitive changes.
Signed licenses
License responses from payfim.com are signed with Ed25519 and verified by your gateway. If payfim.com is ever unreachable, your checkout keeps working.
Reporting a vulnerability
Please email info@payfim.com with the subject "Security". We respond within 48 hours and credit researchers who report responsibly.
