Esta tradução é fornecida para conveniência. A versão em inglês é a que tem valor legal.
1. Key custody
This is the important one, so read it twice. By default the receive addresses are derived from key material held by the Operator, not by you: payments land on the Operator's addresses and are credited to your balance, and you withdraw from there. Signing is not automated — the web application has no path that broadcasts a transfer on its own; withdrawals and payouts are reviewed, signed and broadcast by the Operator outside it. A merchant who does not want the Operator holding their funds at all can ask for derivation from their own xPub; then payments settle to addresses only that merchant controls, and the Operator never has the keys to them.
2. API and webhook integrity
2.1 Signing
API requests and webhooks are signed with HMAC-SHA256, with a timestamp window to bound replay, and idempotency keys so a retried call does not act twice. Signatures are compared in constant time.
2.2 Outbound webhooks
Outbound webhooks are SSRF-guarded: https only, sent to the URL the merchant configured, pinned to a validated IP address, with private, CGNAT and NAT64 ranges denied.
3. Credentials at rest
Passwords are hashed with bcrypt. The api_secret is encrypted at rest with AES-256-GCM. Private keys, seed phrases and card numbers are never stored at all.
4. Account security
Optional TOTP two-factor authentication with recovery codes. Sessions are tracked server-side and can be revoked. CSRF tokens protect state-changing requests. Rate limiting applies per IP and per key.
5. Transport and browser hardening
HSTS, a Content Security Policy, X-Frame-Options set to DENY, X-Content-Type-Options nosniff, and a Referrer-Policy.
6. Money integrity
Settlements are recorded in an append-only ledger with a UNIQUE idempotency anchor, so the same deposit cannot be credited twice. Advisory locks serialise balance changes, so concurrent operations cannot race a balance into the wrong state.
7. What we do not claim
Payora holds no PCI-DSS, SOC 2 or ISO 27001 certification, and no regulator's licence. Anyone telling you otherwise is wrong. The software gives the Operator strong defaults; the security of a running instance also depends on the Operator's server, hosting and practices.
8. Your side of it
Keep your API secret and password private. Turn on two-factor authentication. Verify webhook signatures rather than trusting the payload. Check payout addresses carefully, including any destination tag or memo, because a sent transaction cannot be recalled.
9. Reporting a vulnerability
Report security issues to the Operator at support@payora.money. Please give enough detail to reproduce, and please do not test against other people's accounts or data.
Last updated: 16 July 2026. If we make material changes to this page, the updated version will be posted here.