Zero-Compromise Security

Security & Financial Integrity

Protecting merchant balances and customer payment data with multi-layered cryptography, PIN authorization, and Google SMTP two-factor verification.

Two-Factor Authentication (Email OTP)

Logins and registrations are fortified with a 6-digit cryptographic one-time password delivered directly to the merchant’s registered email via Google SMTP. Access is blocked until the code is verified.

  • 10-minute code expiry window
  • Single-use cryptographic token invalidation
  • Configurable 2FA enforcement in Account Settings

Withdraw Authorization PIN

Even if an account session is compromised, funds cannot be drained without the merchant’s dedicated 4-6 digit numeric Withdraw PIN required before every manual disbursement.

  • Argon2 / Bcrypt cryptographic password hashing
  • Self-service PIN updates with account password confirmation
  • Enforced across all web payout submissions

HMAC-SHA256 Webhook Signatures

Every webhook sent to your server contains an anti-tamper signature generated with your private Webhook Secret. Replay attacks are prevented via embedded timestamp headers.

  • Constant-time cryptographic string verification
  • 5-minute replay attack threshold rejection
  • Custom per-endpoint webhook overrides

Immutable Double-Entry Ledger

Balances are strictly calculated and modified through an immutable ledger audit trail. Every credit, debit, payout fee, and refund records the balance before and balance after with transaction cross-references.

  • Pessimistic database row locking on balance mutations
  • Zero phantom reads or race condition balance inflation
  • 100% auditable accounting entries

Experience secure digital payments

Protect your transactions with HivePay's bank-grade payment gateway.