Skip to main content

Security

Security​

PayWise security is grounded in these principles:

  • Least privilege: Every credential should grant only the actions and environments the client actually needs.
  • Defense in depth: Combine header validation, TLS, and monitoring to detect anomalies early.
  • Auditability: Retain logs per request ID and index X-Request-Id so forensic analysis can reconstruct incidents.

Enable network restrictions on production-only keys, perform regular penetration tests, and keep dependencies up to date to reduce the attack surface.