Security & Financial Integrity
Protecting merchant balances and customer payment data with multi-layered cryptography, PIN authorization, and Google SMTP two-factor verification.
Two-Factor Authentication (Email OTP)
Logins and registrations are fortified with a 6-digit cryptographic one-time password delivered directly to the merchant’s registered email via Google SMTP. Access is blocked until the code is verified.
- 10-minute code expiry window
- Single-use cryptographic token invalidation
- Configurable 2FA enforcement in Account Settings
Withdraw Authorization PIN
Even if an account session is compromised, funds cannot be drained without the merchant’s dedicated 4-6 digit numeric Withdraw PIN required before every manual disbursement.
- Argon2 / Bcrypt cryptographic password hashing
- Self-service PIN updates with account password confirmation
- Enforced across all web payout submissions
HMAC-SHA256 Webhook Signatures
Every webhook sent to your server contains an anti-tamper signature generated with your private Webhook Secret. Replay attacks are prevented via embedded timestamp headers.
- Constant-time cryptographic string verification
- 5-minute replay attack threshold rejection
- Custom per-endpoint webhook overrides
Immutable Double-Entry Ledger
Balances are strictly calculated and modified through an immutable ledger audit trail. Every credit, debit, payout fee, and refund records the balance before and balance after with transaction cross-references.
- Pessimistic database row locking on balance mutations
- Zero phantom reads or race condition balance inflation
- 100% auditable accounting entries
Experience secure digital payments
Protect your transactions with HivePay's bank-grade payment gateway.