XXPayUS / Trust
Security. Without ambiguity.
The controls currently in place to protect payment operations. Provided for transparency — not an independent certification or audit.
Authentication & Access
- Accounts are invite-only and created by the platform owner — there are no anonymous or self-service sign-ups.
- Every user signs in with their own credentials, and sessions are managed by our authentication provider.
- Roles (Admin, Merchant, Agent, Employee) determine what each user can see and do, enforced on the server.
Row-Level Data Protection
- Database access is governed by row-level security so users can only read and modify records that belong to them.
- Financial records such as transactions are restricted to the owning agent, merchant, or an administrator.
- Anonymous (signed-out) visitors cannot read or write protected application data.
Payments & Sensitive Data
- Payment processing is handled through our payment gateway integrations; merchant credentials and signing keys are kept server-side and never exposed to the browser.
- Withdrawals require administrator approval before funds leave the system.
- One-time verification tokens are short-lived and are not readable by other users.
Storage
- Uploaded files such as chat attachments and QR codes are stored in private buckets.
- Only authenticated owners can modify their own stored files.
Platform & Hosting
- XXPayUS runs on managed cloud infrastructure providing database, authentication, storage, and serverless backend services.
- Data is transmitted over encrypted connections (HTTPS) between your device and our services.
Shared Responsibility
- We maintain application access controls and platform configuration described on this page.
- Account holders are responsible for keeping their sign-in credentials confidential and for the activity within their accounts.
Reporting a security concern
If you believe you have found a security or privacy issue, please contact our team so we can investigate promptly.