跳到内容
法律

Security

The controls that actually exist in Payora. No certifications are claimed, because none are held.

最后更新于 2026年7月16日2 分钟阅读章节: 9

1. Key custody

This is the important one, so read it twice. By default the receive addresses are derived from key material held by the Operator, not by you: payments land on the Operator's addresses and are credited to your balance, and you withdraw from there. Signing is not automated — the web application has no path that broadcasts a transfer on its own; withdrawals and payouts are reviewed, signed and broadcast by the Operator outside it. A merchant who does not want the Operator holding their funds at all can ask for derivation from their own xPub; then payments settle to addresses only that merchant controls, and the Operator never has the keys to them.

2. API and webhook integrity

2.1 Signing

API requests and webhooks are signed with HMAC-SHA256, with a timestamp window to bound replay, and idempotency keys so a retried call does not act twice. Signatures are compared in constant time.

2.2 Outbound webhooks

Outbound webhooks are SSRF-guarded: https only, sent to the URL the merchant configured, pinned to a validated IP address, with private, CGNAT and NAT64 ranges denied.

3. Credentials at rest

Passwords are hashed with bcrypt. The api_secret is encrypted at rest with AES-256-GCM. Private keys, seed phrases and card numbers are never stored at all.

4. Account security

Optional TOTP two-factor authentication with recovery codes. Sessions are tracked server-side and can be revoked. CSRF tokens protect state-changing requests. Rate limiting applies per IP and per key.

5. Transport and browser hardening

HSTS, a Content Security Policy, X-Frame-Options set to DENY, X-Content-Type-Options nosniff, and a Referrer-Policy.

6. Money integrity

Settlements are recorded in an append-only ledger with a UNIQUE idempotency anchor, so the same deposit cannot be credited twice. Advisory locks serialise balance changes, so concurrent operations cannot race a balance into the wrong state.

7. What we do not claim

Payora holds no PCI-DSS, SOC 2 or ISO 27001 certification, and no regulator's licence. Anyone telling you otherwise is wrong. The software gives the Operator strong defaults; the security of a running instance also depends on the Operator's server, hosting and practices.

8. Your side of it

Keep your API secret and password private. Turn on two-factor authentication. Verify webhook signatures rather than trusting the payload. Check payout addresses carefully, including any destination tag or memo, because a sent transaction cannot be recalled.

9. Reporting a vulnerability

Report security issues to the Operator at support@payora.money. Please give enough detail to reproduce, and please do not test against other people's accounts or data.

Last updated: 16 July 2026. If we make material changes to this page, the updated version will be posted here.

常见问题

常见问题

直接的答案,包括不太舒服的内容:保管、费用以及当出现问题时会发生什么。

帮助中心

Where are the private keys?

Not on the server. Receive addresses are derived from public key material only, such as an xPub, a master public key or an offline-generated pool, and no spending key is stored on the server. Payouts are signed on the Operator's own machine and broadcast from there.

Is Payora PCI-DSS, SOC 2 or ISO 27001 certified?

No. Payora holds no such certification and no regulator licence, and does not claim any. The software provides strong defaults, but the security of a running instance also depends on the Operator server, hosting and practices.

How is a deposit stopped from being credited twice?

Settlements go into an append-only ledger with a UNIQUE idempotency anchor, so the same deposit cannot be credited twice, and advisory locks serialise balance changes so concurrent operations cannot race the balance.

How do I know a webhook really came from Payora?

Verify the HMAC-SHA256 signature rather than trusting the payload. Signatures use a timestamp window to bound replay and idempotency keys so a retry does not act twice, and are compared in constant time.

此页面回答的问题